GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the system maintenance configuration download handler. The wcf_handle_download() function accepts parameters prefixed with v_del_ and appends their values directly to the base configuration directory path without sanitizing for directory traversal sequences. An authenticated attacker with Admin privileges can read arbitrary files from the system in the context of root.

Project Subscriptions

Vendors Products
Gfi Software Subscribe
Gfi Exinda Ai Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 04 Sep 2026 16:30:00 +0000


Fri, 04 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Gfi Software
Gfi Software gfi Exinda Ai
Vendors & Products Gfi Software
Gfi Software gfi Exinda Ai

Fri, 04 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description GFI Exinda AI before 7.6.5 contains a path traversal vulnerability in the system maintenance configuration download handler. The wcf_handle_download() function accepts parameters prefixed with v_del_ and appends their values directly to the base configuration directory path without sanitizing for directory traversal sequences. An authenticated attacker with Admin privileges can read arbitrary files from the system in the context of root. GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the system maintenance configuration download handler. The wcf_handle_download() function accepts parameters prefixed with v_del_ and appends their values directly to the base configuration directory path without sanitizing for directory traversal sequences. An authenticated attacker with Admin privileges can read arbitrary files from the system in the context of root.
Title GFI Exinda AI < 7.6.5 Path Traversal via Configuration Download Handler GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Configuration Download Handler
References

Fri, 04 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description GFI Exinda AI before 7.6.5 contains a path traversal vulnerability in the system maintenance configuration download handler. The wcf_handle_download() function accepts parameters prefixed with v_del_ and appends their values directly to the base configuration directory path without sanitizing for directory traversal sequences. An authenticated attacker with Admin privileges can read arbitrary files from the system in the context of root.
Title GFI Exinda AI < 7.6.5 Path Traversal via Configuration Download Handler
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-04T15:15:45.935Z

Reserved: 2026-08-14T18:01:19.917Z

Link: CVE-2026-74235

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T13:20:08.217

Modified: 2026-09-04T16:17:57.137

Link: CVE-2026-74235

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T17:30:17Z

Weaknesses