Arbitrary Directory Enumeration Vulnerability in GFI MailEssentials AI
CVE-2026-23621

5.3MEDIUM

Key Information:

Vendor
CVE Published:
19 February 2026

What is CVE-2026-23621?

GFI MailEssentials AI versions prior to 22.4 are susceptible to an arbitrary directory enumeration vulnerability found in the ListServer.IsPathExist() web method. This flaw allows authenticated users to submit unrestricted file system paths via a JSON key. The path is then URL-decoded and passed to the Directory.Exists() method, thereby enabling potential attackers to ascertain the existence of arbitrary directories on the server, which could lead to further exploitation.

Affected Version(s)

MailEssentials AI 0 < 22.4

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Williams from Pellera Technologies
VulnCheck
.