Executive brief
Next4Biz CSM is a customer service management platform used by organizations to handle support tickets and customer interactions. A critical vulnerability in CSM versions before 8.0.3 allows attackers to inject and execute arbitrary code through deserialization of malicious data, potentially compromising the entire system and all customer data managed within it.
Technical details
The vulnerability is a deserialization of untrusted data flaw in Next4Biz CSM that enables code injection attacks. The vulnerable component improperly deserializes untrusted input without validation, allowing attackers to craft malicious serialized objects that execute arbitrary code when deserialized. Attack exploitation requires network access to the vulnerable CSM instance; authentication requirements are not specified but deserialization flaws are often exploitable without authentication. Successful exploitation grants remote code execution with the privileges of the CSM application process. The fix is available in version 8.0.3 and later.
Affected products
- Next4Biz Information Technologies Inc. CSM before 8.0.3
Timeline
- 2026-09-07: disclosed