CVE-2026-2604
CWE-73Published: June 17, 2026· Updated: Jun 17, 2026
Official Description
A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.
Technical Analysis
CVE-2026-2604 requires local access, meaning attackers must already have a foothold on the target system.
Exploitation requires low privileges, which limits the exposure to scenarios where an attacker has already gained initial access.
A successful exploit results in full integrity compromise (data manipulation), with a CVSS base score of 5.6.
CVSS v3.1 Vector Breakdown
Exploit & PoC Resources
News & Research Mentioning CVE-2026-2604
View CSAF Summary Successful exploitation of these vulnerabilities could result in authentication being disabled, a denial-of-service condition, or an attacker stealing valid user credentials, including administrator credentials. The following versions of Jinan USR IOT Technology Limited (PUSR) USR-W610 are affected: USR-W610 <=3.1.1.0 (CVE-2026-25715, CVE-2026-24455, CVE-2026-26049, CVE-2026-26048) CVSS Vendor Equipment Vulnerabilities v3 9.8 Jinan USR IOT Technology Limited (PUSR) Jinan USR IOT Technology Limited (PUSR) USR-W610 Weak Password Requirements, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials, Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Critical Manufactur [xlite_meta score:73 src:CISA Alerts xlite_fp:8491874e48185311f9bbfa42b476a6554960dc0aa0006292b37523eb314023bc]
All References (5)
Quick Facts
Related CVEs (CWE-73)
Recommended Actions
- →Apply vendor patches immediately
- →Monitor CVE-2026-2604 in threat intel feeds
- →Review IDS/IPS signatures for exploitation attempts