CVE-2026-2604Patch

LOWCVSS 5.6 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-23: 1Patch / Workaround · 2026-02-23: 102-23
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 URGENT #UBUNTU SECURITY UPDATE 🚨 USN-8055-1 addresses a file removal vulnerability in evolution-data-server (CVE-2026-2604). Affects 22.04, 24.04, & 25.10. Read more: 👉 https://tinyurl.com/46yuzzbx #Security https://t.co/bSILzxSpAf

    Post summary

    Ubuntu releases USN‑8055‑1 to patch a file removal vulnerability in evolution‑data‑server (CVE‑2026‑2604) affecting releases 22.04, 24.04, and 25.10.

    0000065
    1.3K followersView on X

Explore more