PT-2026-85518 · Gfi · Gfi Clearview+1

·

CVE-2026-74236

·

Published

2026-09-04

·

Updated

2026-09-04

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions GFI Exinda AI versions prior to 7.6.5 GFI ClearView versions prior to 7.6.5
Description A path traversal issue exists in the diagnostic file deletion handler. The unlink or email file() function processes parameters prefixed with v file row and appends their values to a base directory path without sanitizing for directory traversal sequences. This allows an authenticated attacker with Admin privileges to delete arbitrary files from the system with root permissions.
Recommendations Update GFI Exinda AI to version 7.6.5 or later. Update GFI ClearView to version 7.6.5 or later.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74236

Affected Products

Gfi Clearview
Gfi Exinda Ai