🔐 CVE Alert

CVE-2026-23621

MEDIUM 4.3

GFI MailEssentials AI < 22.4 ListServer.IsPathExist() Absolute Directory Traversal to File Enumeration

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

GFI MailEssentials AI versions prior to 22.4 contain an arbitrary directory existence enumeration vulnerability in the ListServer.IsPathExist() web method exposed at /MailEssentials/pages/MailSecurity/ListServer.aspx/IsPathExist. An authenticated user can supply an unrestricted filesystem path via the JSON key \"path\", which is URL-decoded and passed to Directory.Exists(), allowing the attacker to determine whether arbitrary directories exist on the server.

CWE CWE-203
Vendor gfi software
Product mailessentials ai
Published Feb 19, 2026
Last Updated Mar 2, 2026
Stay Ahead of the Next One

Get instant alerts for gfi software mailessentials ai

Be the first to know when new medium vulnerabilities affecting gfi software mailessentials ai are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

GFI Software / MailEssentials AI
0 < 22.4

References

NVD ↗ CVE.org ↗ EPSS Data ↗
gfi.ai: https://gfi.ai/products-and-solutions/network-security-solutions/mailessentials/resources/documentation/product-releases vulncheck.com: https://www.vulncheck.com/advisories/gfi-mailessentials-ai-listserver-ispathexist-absolute-directory-traversal-to-file-enumeration

Credits

Alex Williams from Pellera Technologies VulnCheck