SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-74235

MEDIUM · CVSS 4.9 EPSS 0.56%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

GFI Exinda AI and ClearView versions prior to 7.6.5 are vulnerable to a path traversal flaw in the system maintenance configuration download handler, allowing an authenticated attacker with Admin privileges to access arbitrary files on the system. This could lead to unauthorized disclosure of sensitive information, as the vulnerability permits reading files in the context of the root directory. Organizations using these products should prioritize patching to mitigate potential data exposure risks.

CVE
CVE-2026-74235
Severity
MEDIUM
CVSS
4.9
EPSS
0.56%

Original NVD Description

GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the system maintenance configuration download handler. The wcf_handle_download() function accepts parameters prefixed with v_del_ and appends their values directly to the base configuration directory path without sanitizing for directory traversal sequences. An authenticated attacker with Admin privileges can read arbitrary files from the system in the context of root.