No analysis available yet.
Vendor Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4503-1 | evolution-data-server security update |
Ubuntu USN |
USN-8055-1 | Evolution Data Server vulnerability |
Ubuntu USN |
USN-8055-2 | Evolution Data Server vulnerability |
Tue, 16 Jun 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 16 Jun 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files. |
| Title | evolution-data-server: Evolution Data Server: Arbitrary file deletion via inconsistent URI handling | Evolution-data-server: evolution data server: arbitrary file deletion via inconsistent uri handling |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
|
Tue, 17 Feb 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gnome
Gnome evolution-data-server |
|
| Vendors & Products |
Gnome
Gnome evolution-data-server |
Tue, 17 Feb 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | |
| Title | evolution-data-server: Evolution Data Server: Arbitrary file deletion via inconsistent URI handling | |
| Weaknesses | CWE-73 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-06-16T22:41:46.755Z
Reserved: 2026-02-16T21:29:35.465Z
Link: CVE-2026-2604
No data.
No data.
OpenCVE Enrichment
Updated: 2026-02-17T08:56:24Z
-
CWE-73
External Control of File Name or Path
Debian DLA
Ubuntu USN