ZeroHour

CVE-2026-6377

niche

Unauthenticated Path Traversal in Next4Biz CSM (Customer Service Management)

CVSS 3.1
7.5 high
EPSS
<1%p27
Published
()
Modified
AI analysis

CVE-2026-6377 is a path traversal vulnerability (CWE-22, Improper Limitation of a Pathname to a Restricted Directory) in Next4Biz Information Technologies Inc.'s CSM (Customer Service Management) product. It is triggered when user-supplied path input is not properly restricted to an intended directory, and because the CVSS 3.1 vector shows a network attack vector with no privileges or user interaction required (AV:N/AC:L/PR:N/UI:N), an unauthenticated remote attacker can send crafted requests to a network-reachable CSM interface to traverse outside the restricted directory. The impact is limited to information disclosure (C:H with no integrity or availability impact), meaning an attacker can likely read files outside the intended directory on the affected deployment; the CVSS 3.1 base score is 7.5 (High). Any organization running CSM versions from 6.8.9 up to but not including 8.0.3 is affected, with 8.0.3 being the fixed release. There is currently no known public proof-of-concept or in-the-wild exploitation, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns a 0.3% probability of exploitation within 30 days (27th percentile).

What to do: Upgrade Next4Biz CSM to version 8.0.3 or later, the first release outside the affected range. If patching is delayed, restrict internet-facing access to the CSM application and review access logs for path-traversal patterns in unauthenticated requests. Given no public PoC and a low EPSS score (0.3%), this fits within normal patch cycles, but internet-exposed deployments should prioritize the upgrade.

Affected
Next4Biz Information Technologies Inc. CSM (Customer Service Management)>= 6.8.9 and < 8.0.3
Estimated exposure
nicheOn the order of hundreds to a few thousand deployments (estimate; no public install counts available) — Next4Biz CSM is an enterprise customer-service platform from a single, relatively small vendor, typically deployed once per customer organization rather than at internet scale, and no public install-base or internet-exposure scan counts…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Path Traversal. This issue affects CSM (Customer Service Management): from 6.8.9 before 8.0.3.

Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.