CVE-2026-74235: GFI Exinda AI < 7.6.5 Path Traversal via Configuration Download Handler

Published Sep 4, 2026
·
Updated

GFI Exinda AI before 7.6.5 contains a path traversal vulnerability in the system maintenance configuration download handler. The wcfhandledownload() function accepts parameters prefixed with vdel and appends their values directly to the base configuration directory path without sanitizing for directory traversal sequences. An authenticated attacker with Admin privileges can read arbitrary files from the system in the context of root.

Affected Software

1 affected component
GFI Exinda AI<7.6.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade GFI Exinda AI to a version that resolves this vulnerability.

    Fixed in 7.6.5
  2. Configuration

    Modify wcf_handle_download() so that parameters prefixed with v_del_ are sanitized/validated before being appended to the base configuration directory path, preventing directory traversal.

    GFI Exinda AI system maintenance configuration download handler Input parameters prefixed with v_del_ (e.g., v_del_*) = Do not append raw v_del_* values to the base configuration directory path; sanitize/validate to prevent directory traversal sequences

Event History

Sep 4, 2026
CVE Published
via MITRE·12:22 PM
Data Sourced
via MITRE·12:22 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must already be authenticated to GFI Exinda AI with Admin privileges. The vulnerable handler is reachable over the network, but no user interaction is required.

2

What is the impact of successful exploitation?

An Admin-level attacker can use directory traversal sequences in v_del_ parameter values to read arbitrary files from the system. Files are accessed in the context of root, which may expose sensitive system or application data.

3

Which versions are affected?

GFI Exinda AI versions before 7.6.5 are affected. Updating to 7.6.5 or later addresses the affected version range identified here.

4

What can be done if an update cannot be applied immediately?

Restrict Admin access to trusted users and limit network access to the management interface. Because exploitation requires Admin authentication, reviewing and reducing unnecessary Admin accounts can reduce exposure.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203