CVE-2026-2604Medium· 5.6▾ TwilightPoC availableA flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 30.8 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-91839High· 7.8A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager
CVE-2026-91841High· 7.8A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager
CVE-2026-91840High· 7.8A flaw was found in NetworkManager-vpnc
CVE-2026-88924High· 7.0Gvfs: gvfs-admin socket ownership race permits local root
CVE-2026-58014High· 7.3A flaw was found in GLib
CVE-2026-58011Medium· 6.5A flaw was found in GLib