SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-6377

HIGH · CVSS 7.5 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A path traversal vulnerability in Next4Biz Information Technologies Inc.'s Customer Service Management (CSM) software allows attackers to access restricted directories, potentially leading to unauthorized data exposure. Organizations using CSM versions from 6.8.9 to 07092026 should prioritize patching this issue due to its high severity rating, as it poses significant risks to data integrity and confidentiality. Immediate action is recommended, especially since the vendor has not responded to disclosure efforts.

CVE
CVE-2026-6377
Severity
HIGH
CVSS
7.5
EPSS
0.34%

Original NVD Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Path Traversal. This issue affects CSM (Customer Service Management): from 6.8.9 before 8.0.3.