A critical (CVSS 9.8) deserialization of untrusted data vulnerability in Next4Biz CSM enables remote code injection without authentication or user interaction, and the vendor has not responded to disclosure attempts.
What Is It
CVE-2026-7861 is a deserialization of untrusted data vulnerability (CWE-502) in Next4Biz Information Technologies Inc.'s CSM (Customer Service Management) platform. The flaw allows Code Injection, meaning an attacker who can reach the application over the network can supply crafted serialized data that the application deserializes and acts upon.
The CVE was assigned and published on 2026-09-07 by USOM (the Turkish national CSIRT, [email protected]) acting as CNA, and currently carries a "Received" NVD status.
Why It Matters
The vulnerability is rated CVSS 3.1 base score 9.8 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Every exploitability factor is worst-case: network attack vector, low attack complexity, no privileges required, and no user interaction. Impact is high across confidentiality, integrity, and availability; an exploitability subscore of 3.9 (the maximum) paired with an impact subscore of 5.9.
Deserialization flaws of this class typically hand the attacker code execution in the context of the application. Because CSM platforms sit at the customer-facing edge and hold customer records, the exposure is both direct and data-heavy.
Notably, the CVE record states the vendor was contacted early about this disclosure but did not respond in any way.
What's Vulnerable
- Vendor: Next4Biz Information Technologies Inc.
- Product: CSM (Customer Service Management)
- Affected versions: all versions from
0through07092026(a date-based version string), per the CNA-supplied affected-version range. Default status for versions outside that range is listed as "unknown."
No CPE matches are currently published for this CVE.
Patch Status
No patch, fixed version, or vendor remediation guidance is present in the supplied source material. The vendor did not respond to disclosure outreach, so no fix should be assumed available. This CVE does not appear in the supplied CISA KEV data; there is no confirmation of active exploitation, and no KEV-mandated required action or due date applies.
Given the absence of a vendor fix, defenders should treat network exposure reduction as the practical lever until Next4Biz issues guidance.
Sources
- NVD, CVE-2026-7861: https://nvd.nist.gov/vuln/detail/CVE-2026-7861
- USOM advisory reference carried in the CVE record, cited as TR-26-1027: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1027