HIGH 7.0 NVD
CVE-2026-74236
GFI Exinda AI before 7.6.5 contains a path traversal vulnerability in the diagnostic file deletion handler. The unlink_or_email_file() function accepts paramete
GFI Exinda AI before 7.6.5 contains a path traversal vulnerability in the diagnostic file deletion handler. The unlink_or_email_file() function accepts parameters prefixed with v_file_row_ and appends their values directly to a base directory path without sanitizing for directory traversal sequences. An authenticated attacker with Admin privileges can delete arbitrary files from the system in the context of root.
References
- https://gfi.ai/products-and-solutions/network-management-solutions/exinda-networkorchestra
- https://www.vulncheck.com/advisories/gfi-exinda-ai-path-traversal-via-diagnostic-file-dele
This high severity vulnerability with a CVSS score of 7.0 was published on 2026-09-04 via NVD.
vulnfeed aggregates 8217 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.