CVE-2026-6377: Path Traversal in Next4Biz's CSM (Customer Service Management)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Path Traversal.
This issue affects CSM (Customer Service Management): from 6.8.9 through 07092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict external access to the Next4Biz CSM application (Customer Service Management) to reduce exposure to path traversal attempts until a vendor fix is available.
Event History
Frequently Asked Questions
Which deployments are affected?
The issue affects Next4Biz CSM (Customer Service Management) versions from 6.8.9 through 07092026.
Does exploitation require authentication or user interaction?
No. The supplied CVSS vector indicates network-reachable exploitation with low attack complexity, no privileges required, and no user interaction.
What is the likely security impact?
The CVSS vector indicates high confidentiality impact, with no integrity or availability impact stated. A successful path traversal attack may therefore expose data accessible through affected paths.
Is a vendor fix or mitigation available?
The provided information does not identify a fixed version or workaround. It states that the vendor was contacted early but did not respond.