CVE-2026-74235 | GFI Exinda AI up to 7.6.4 Download wcf_handle_download v_del_ path traversal

SecurityVulns

A vulnerability classified as problematic has been found in GFI Exinda AI up to 7.6.4. The affected element is the function wcf_handle_download of the component Download Handler. The manipulation of the argument v_del_ leads to path traversal.

This vulnerability is traded as CVE-2026-74235. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More