Bug 2529481 (CVE-2026-6377)

Summary: CVE-2026-6377 CSM: Next4Biz CSM: Information disclosure via path traversal vulnerability
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: aazores, akhatavk, akoudelk, alebedev, amctagga, anjoseph, anthomas, aoconnor, aos-team-art-private, aruklets, asdas, bniver, cmah, cmyers, dnakabaa, doconnor, dpaolell, dymurray, eaguilar, ebaron, eborisov, ehelms, flucifre, ggainey, gmeno, gparvin, groman, ibolton, jcantril, jdelft, jmatsuok, jmatthew, jmontleo, jpasqual, jprabhak, jtolenti, jupierce, juwatts, kaycoth, lball, lbragsta, lchilton, lcouzens, lgamliel, lgarciaa, mbenjamin, mbiarnes, mdellweg, mhackett, mhulan, ngough, nmoumoul, osousa, pcreech, pgaikwad, pjindal, ppalepu, ppostler, prdhamdh, rchan, rekumar, rhaigner, rhel-process-autobot, rjohnson, rojacob, sakbas, sbratsla, sfeifer, sghai, sidsharm, slucidi, smallamp, sostapov, sseago, suppawar, tmalecek, vereddy, veshanka, vlaad, vvoronko, watson-tool-maintainers, wenshen, whayutin, wtam
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-07 14:33:54 UTC
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Path Traversal.

This issue affects CSM (Customer Service Management): from 6.8.9 through 07092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.