Arbitrary Directory Enumeration Vulnerability in GFI MailEssentials AI
CVE-2026-23621
5.3MEDIUM
What is CVE-2026-23621?
GFI MailEssentials AI versions prior to 22.4 are susceptible to an arbitrary directory enumeration vulnerability found in the ListServer.IsPathExist() web method. This flaw allows authenticated users to submit unrestricted file system paths via a JSON key. The path is then URL-decoded and passed to the Directory.Exists() method, thereby enabling potential attackers to ascertain the existence of arbitrary directories on the server, which could lead to further exploitation.
Affected Version(s)
MailEssentials AI 0 < 22.4
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Alex Williams from Pellera Technologies
VulnCheck
