CVE-2026-23620
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
19/02/2026
Last modified:
20/02/2026
Description
GFI MailEssentials AI versions prior to 22.4 contain an arbitrary file existence enumeration vulnerability in the ListServer.IsDBExist() web method exposed at /MailEssentials/pages/MailSecurity/ListServer.aspx/IsDBExist. An authenticated user can supply an unrestricted filesystem path via the JSON key \"path\", which is URL-decoded and passed to File.Exists(), allowing the attacker to determine whether arbitrary files exist on the server.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM
Base Score 3.x
4.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:gfi:mailessentials:*:*:*:*:*:*:*:* | 22.4 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



