PT-2026-85517 · Gfi · Clearview+1

·

CVE-2026-74235

·

Published

2026-09-04

·

Updated

2026-09-04

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GFI Exinda AI versions prior to 7.6.5 GFI ClearView versions prior to 7.6.5
Description A path traversal issue exists in the system maintenance configuration download handler. The wcf handle download() function fails to sanitize parameters prefixed with v del before appending them to the base configuration directory path. This allows an authenticated attacker with Admin privileges to read arbitrary files from the system with root permissions. Path traversal is a technique used to access files and directories that are stored outside the web root folder.
Recommendations Update GFI Exinda AI to version 7.6.5 or later. Update GFI ClearView to version 7.6.5 or later.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74235

Affected Products

Clearview
Exinda Ai