CVE-2026-2604

A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.
Configurations

No configuration.

History

17 Jun 2026, 16:14

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-17 13:20

Updated : 2026-06-17 16:14


NVD link : CVE-2026-2604

Mitre link : CVE-2026-2604

CVE.ORG link : CVE-2026-2604


JSON object : View

Products Affected

No product.

CWE
CWE-73

External Control of File Name or Path