CVE-2026-7861
nicheUnauthenticated Deserialization RCE in Next4Biz CSM
Next4Biz CSM (Customer Service Management) versions before 8.0.3 deserialize untrusted data without validation (CWE-502), allowing attackers to inject and execute arbitrary code. The flaw is triggered by sending crafted serialized data to the network-facing application, with no authentication, privileges, or user interaction required (CVSS 3.1: AV:N/AC:L/PR:N/UI:N). A successful attack yields full compromise of the hosting server, with high impact to confidentiality, integrity, and availability, effectively enabling remote code execution. Any organization running an affected version of Next4Biz CSM is at risk, particularly instances exposed to the internet. No public proof-of-concept or confirmed exploitation is known; EPSS currently estimates only a ~0.3% probability of exploitation within 30 days, and the issue is not in CISA KEV.
What to do: Upgrade Next4Biz CSM to version 8.0.3 or later. Until patched, restrict network access to the CSM instance (e.g., firewall rules, VPN, or WAF filtering of serialized input) and avoid exposing it directly to the internet. Monitor vendor advisories and server logs for signs of unexpected deserialization traffic or code execution.
| Next4Biz Information Technologies Inc. CSM (Customer Service Management) | before 8.0.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Customer Service Management): before 8.0.3.
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.