Description
GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the diagnostic file deletion handler. The unlink_or_email_file() function accepts parameters prefixed with v_file_row_ and appends their values directly to a base directory path without sanitizing for directory traversal sequences. An authenticated attacker with Admin privileges can delete arbitrary files from the system in the context of root.
Published: 2026-09-04
Score: 7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

GFI Exinda AI and ClearView before 7.6.5 contain a path traversal flaw in the diagnostic file deletion handler. The unlink_or_email_file() function accepts parameters prefixed with v_file_row_ and concatenates these values to a base directory without sanitizing for directory traversal sequences. An authenticated attacker who has Admin privileges can supply crafted input to delete arbitrary files in the system context as root, which can destroy critical configuration, operating system files, and cause a denial‑of‑service.

Affected Systems

GFI Software’s GFI ClearView and GFI Exinda AI network orchestration platforms, versions earlier than 7.6.5, are affected. The vulnerability exists in the diagnostic module that processes file‑deletion requests through the web interface; any installation using a pre‑7.6.5 release is at risk.

Risk and Exploitability

The CVSS score of 7.0 indicates significant impact, and the weakness is classified as CWE‑22. Because the flaw requires an authenticated admin user, the attack vector is limited to users with elevated rights. However, once authorized, the attacker can delete any file on the host, effectively achieving root‑level destruction and potentially allowing further exploitation. No current public exploit is documented, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is unavailable, so the precise likelihood of exploitation is unknown, but the high severity and privileged access requirement make it a priority for patching.

Generated by OpenCVE AI on September 4, 2026 at 16:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade GFI Exinda AI to version 7.6.5 or later.
  • Restrict admin privileges to only essential personnel and enable multi‑factor authentication for admin accounts.
  • If an immediate upgrade is not possible, consider disabling the diagnostic file deletion interface or blocking its access from untrusted networks.

Generated by OpenCVE AI on September 4, 2026 at 16:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 16:30:00 +0000


Fri, 04 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Gfi Software
Gfi Software gfi Exinda Ai
Vendors & Products Gfi Software
Gfi Software gfi Exinda Ai

Fri, 04 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description GFI Exinda AI before 7.6.5 contains a path traversal vulnerability in the diagnostic file deletion handler. The unlink_or_email_file() function accepts parameters prefixed with v_file_row_ and appends their values directly to a base directory path without sanitizing for directory traversal sequences. An authenticated attacker with Admin privileges can delete arbitrary files from the system in the context of root. GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the diagnostic file deletion handler. The unlink_or_email_file() function accepts parameters prefixed with v_file_row_ and appends their values directly to a base directory path without sanitizing for directory traversal sequences. An authenticated attacker with Admin privileges can delete arbitrary files from the system in the context of root.
Title GFI Exinda AI < 7.6.5 Path Traversal via Diagnostic File Deletion Handler GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Diagnostic File Deletion Handler
References

Fri, 04 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description GFI Exinda AI before 7.6.5 contains a path traversal vulnerability in the diagnostic file deletion handler. The unlink_or_email_file() function accepts parameters prefixed with v_file_row_ and appends their values directly to a base directory path without sanitizing for directory traversal sequences. An authenticated attacker with Admin privileges can delete arbitrary files from the system in the context of root.
Title GFI Exinda AI < 7.6.5 Path Traversal via Diagnostic File Deletion Handler
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Gfi Software Gfi Exinda Ai
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-04T15:15:34.135Z

Reserved: 2026-08-14T18:01:19.917Z

Link: CVE-2026-74236

cve-icon Vulnrichment

Updated: 2026-09-04T13:04:49.814Z

cve-icon NVD

Status : Received

Published: 2026-09-04T13:20:08.420

Modified: 2026-09-04T16:17:57.257

Link: CVE-2026-74236

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T17:00:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')