Arbitrary File Enumeration Vulnerability in GFI MailEssentials AI
CVE-2026-23620

5.3MEDIUM

Key Information:

Vendor
CVE Published:
19 February 2026

What is CVE-2026-23620?

GFI MailEssentials AI versions before 22.4 have a vulnerability that allows an authenticated user to exploit the ListServer.IsDBExist() method. By supplying an unrestricted filesystem path through the 'path' JSON key, an attacker can leverage this flaw to determine the existence of arbitrary files on the server, potentially leading to further exploitation. This highlights the need for ensuring proper access controls and input validation to mitigate risks associated with file enumeration.

Affected Version(s)

MailEssentials AI 0 < 22.4

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Williams from Pellera Technologies
VulnCheck
.