Arbitrary File Enumeration Vulnerability in GFI MailEssentials AI
CVE-2026-23620
5.3MEDIUM
What is CVE-2026-23620?
GFI MailEssentials AI versions before 22.4 have a vulnerability that allows an authenticated user to exploit the ListServer.IsDBExist() method. By supplying an unrestricted filesystem path through the 'path' JSON key, an attacker can leverage this flaw to determine the existence of arbitrary files on the server, potentially leading to further exploitation. This highlights the need for ensuring proper access controls and input validation to mitigate risks associated with file enumeration.
Affected Version(s)
MailEssentials AI 0 < 22.4
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Alex Williams from Pellera Technologies
VulnCheck
