Path Traversal Vulnerability in GFI Exinda AI Network Management Solution
CVE-2026-74236

7HIGH

Key Information:

Vendor
CVE Published:
4 September 2026

What is CVE-2026-74236?

GFI Exinda AI prior to version 7.6.5 is susceptible to a path traversal vulnerability within its diagnostic file deletion handler. This issue arises when the unlink_or_email_file() function fails to properly sanitize user-supplied input prefixed with v_file_row_. By appending these values directly to a base directory path without validation, an authenticated attacker with Admin privileges can exploit this vulnerability to delete arbitrary files from the system, potentially leading to elevated risks and loss of sensitive data.

Affected Version(s)

GFI Exinda AI 0 < 7.6.5

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Williams of Pellera Technologies
VulnCheck
.