---
id: CVE-2026-74236
title: >-
  GFI Exinda AI and ClearView before 7.6.5 contains a path traversal
  vulnerability in the diagnostic file deletion handler
summary: >-
  GFI Exinda AI and ClearView before 7.6.5 contains a path traversal
  vulnerability in the diagnostic file deletion handler. The
  unlink_or_email_file() function accepts parameters prefixed with v_file_row_
  and appends their values directly …
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-22
published: '2026-09-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:10:30.270'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-74236'
references:
  - url: >-
      https://gfi.ai/products-and-solutions/network-management-solutions/exinda-networkorchestrator/resources/documentation/product-releases
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/gfi-exinda-ai-clearview-path-traversal-via-diagnostic-file-deletion-handler
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00644
epssPercentile: 0.49487
ingestedAt: '2026-09-08T21:11:12.294Z'
---

## Overview

GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the diagnostic file deletion handler. The unlink_or_email_file() function accepts parameters prefixed with v_file_row_ and appends their values directly to a base directory path without sanitizing for directory traversal sequences. An authenticated attacker with Admin privileges can delete arbitrary files from the system in the context of root.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
