CVE Feed

    Dashboard / CVE / CVE-2026-74235

    CVE-2026-74235

    GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the system maintenance configuration download handler. The wcf_handle_download() function accepts parameters prefixed with v_del_ and appends their values directly to the base configuration directory path without sanitizing for directory traversal sequences. An authenticated attacker with Admin privileges can read arbitrary files from the system in the context of root.

    Published:Sep 4, 2026
    Last Modified:Sep 8, 2026
    EPS:Sep 4, 2026
    EPSS Score:0.00559
    CVSS Score:4.9

    Affected Products

    Vendor
    Gfi Software
    Product
    Gfi Exinda Ai

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High