PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-2604 GNOME CVE debrief

A flaw in evolution-data-server allows a Flatpak application with D-Bus access to delete arbitrary files on the host filesystem by crafting a malicious URI. This issue is rated as MEDIUM with a CVSS score of 5.6. The vulnerability arises from inconsistent comparison logic in the addressbook file backend, which enables a Flatpak application to potentially delete critical system files, elevate privileges, and compromise sensitive data. Defenders responsible for managing evolution-data-server installations, especially in environments with untrusted Flatpak applications, should assess exposure and prioritize patching.

Vendor
GNOME
Product
evolution-data-server
CVSS
MEDIUM 5.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-17
Original CVE updated
2026-09-25
Advisory published
2026-06-17
Advisory updated
2026-09-25

Who should care

Defenders responsible for managing evolution-data-server installations, especially in environments with untrusted Flatpak applications, should assess exposure and prioritize patching.

Why it matters

The CVE-2026-2604 flaw in evolution-data-server allows a Flatpak application with D-Bus access to delete arbitrary files on the host filesystem. Defenders should prioritize verifying and patching evolution-data-server installations, especially in environments with untrusted Flatpak applications, to prevent potential elevation of privileges and compromise of sensitive data.

  • Potential deletion of critical system files
  • Elevation of privileges for untrusted Flatpak applications
  • Compromise of sensitive data through file deletion
  • Verification of evolution-data-server installations and patches

Technical summary

The evolution-data-server flaw allows a Flatpak application with D-Bus access to craft a malicious URI, potentially leading to the deletion of arbitrary files on the host filesystem. This occurs due to inconsistent comparison logic in the addressbook file backend. The URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, enabling the deletion of critical system files. Defenders should prioritize verifying and patching evolution-data-server installations, especially in environments with untrusted Flatpak applications.

Defensive priority

Defenders should prioritize verifying and patching evolution-data-server installations, especially in environments with untrusted Flatpak applications.

Recommended defensive actions

  • Verify and apply patches for evolution-data-server
  • Restrict D-Bus access for untrusted Flatpak applications
  • Monitor for suspicious activity related to contact creation and deletion
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the flaw in evolution-data-server, including its CVSS score and potential impact. The flaw allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. The source detail is limited, so defenders should focus

Sources and references

Verified primary and authoritative sources

  • CVE-2026-2604 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-2604

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-2604 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-2604

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/security/cve/CVE-2026-2604

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://gitlab.gnome.org/GNOME/evolution-data-server/-/issues/627

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://lists.debian.org/debian-lts-announce/2026/03/msg00007.html

    af854a3a-2127-422b-91ae-364da2661108

  • Source reference

    Unverified legacy reference

    URL: https://lists.debian.org/debian-lts-announce/2026/09/msg00031.html

    af854a3a-2127-422b-91ae-364da2661108

  • Source reference

    Unverified legacy reference

    URL: https://gitlab.gnome.org/GNOME/evolution-data-server/-/work_items/627

    134c704f-9b21-4f2e-91b3-4a467353bcc0

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.