CVE-2026-6377
nicheUnauthenticated Path Traversal in Next4Biz CSM (Customer Service Management)
CVE-2026-6377 is a path traversal vulnerability (CWE-22, Improper Limitation of a Pathname to a Restricted Directory) in Next4Biz Information Technologies Inc.'s CSM (Customer Service Management) product. It is triggered when user-supplied path input is not properly restricted to an intended directory, and because the CVSS 3.1 vector shows a network attack vector with no privileges or user interaction required (AV:N/AC:L/PR:N/UI:N), an unauthenticated remote attacker can send crafted requests to a network-reachable CSM interface to traverse outside the restricted directory. The impact is limited to information disclosure (C:H with no integrity or availability impact), meaning an attacker can likely read files outside the intended directory on the affected deployment; the CVSS 3.1 base score is 7.5 (High). Any organization running CSM versions from 6.8.9 up to but not including 8.0.3 is affected, with 8.0.3 being the fixed release. There is currently no known public proof-of-concept or in-the-wild exploitation, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns a 0.3% probability of exploitation within 30 days (27th percentile).
What to do: Upgrade Next4Biz CSM to version 8.0.3 or later, the first release outside the affected range. If patching is delayed, restrict internet-facing access to the CSM application and review access logs for path-traversal patterns in unauthenticated requests. Given no public PoC and a low EPSS score (0.3%), this fits within normal patch cycles, but internet-exposed deployments should prioritize the upgrade.
| Next4Biz Information Technologies Inc. CSM (Customer Service Management) | >= 6.8.9 and < 8.0.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Path Traversal. This issue affects CSM (Customer Service Management): from 6.8.9 before 8.0.3.
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.