Back to overview

CVE-2026-2604

MEDIUM Exploitation: PoC
5.6
CVSS 3.1
Description
A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.

Metadata

CVE ID
CVE-2026-2604
State
PUBLISHED
Assigner
redhat
Reserved
2026-02-16 21:29 UTC
Published
2026-06-16 21:35 UTC
Last updated
2026-06-17 12:46 UTC
Primary CWE
CWE-73
External Control of File Name or Path
Vendor / Product
GNOME / Evolution Data Server
Sources
cve.org  ·  NVD

Severity & Metrics

5.6 MEDIUM CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
partial
Affected products (6)
VendorProductPlatformVersions
GNOME Evolution Data Server 0 < 3.59.3
Red Hat Red Hat Enterprise Linux 10
Red Hat Red Hat Enterprise Linux 6
Red Hat Red Hat Enterprise Linux 7
Red Hat Red Hat Enterprise Linux 8
Red Hat Red Hat Enterprise Linux 9
Weakness (CWE)
CWESourceDescription
CWE-73 cna External Control of File Name or Path
CVSS scores (1)
ScoreSeverityVersionSourceVector
5.6 MEDIUM 3.1 cna CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L
Back to overview