Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GFI Exinda AI before 7.6.5 contains a path traversal vulnerability in the diagnostic file deletion handler. The unlink_or_email_file() function accepts parameters prefixed with v_file_row_ and appends their values directly to a base directory path without sanitizing for directory traversal sequences. An authenticated attacker with Admin privileges can delete arbitrary files from the system in the context of root. | |
| Title | GFI Exinda AI < 7.6.5 Path Traversal via Diagnostic File Deletion Handler | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T13:05:43.074Z
Reserved: 2026-08-14T18:01:19.917Z
Link: CVE-2026-74236
No data.
Status : Received
Published: 2026-09-04T13:20:08.420
Modified: 2026-09-04T13:20:08.420
Link: CVE-2026-74236
No data.
OpenCVE Enrichment
Updated: 2026-09-04T13:30:05Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')