Path Traversal Vulnerability in GFI Exinda AI Network Management Solution
CVE-2026-74236
7HIGH
What is CVE-2026-74236?
GFI Exinda AI prior to version 7.6.5 is susceptible to a path traversal vulnerability within its diagnostic file deletion handler. This issue arises when the unlink_or_email_file() function fails to properly sanitize user-supplied input prefixed with v_file_row_. By appending these values directly to a base directory path without validation, an authenticated attacker with Admin privileges can exploit this vulnerability to delete arbitrary files from the system, potentially leading to elevated risks and loss of sensitive data.
Affected Version(s)
GFI Exinda AI 0 < 7.6.5
References
CVSS V4
Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Alex Williams of Pellera Technologies
VulnCheck
