PatchSiren cyber security CVE debrief
CVE-2026-2604 GNOME CVE debrief
A flaw in evolution-data-server allows a Flatpak application with D-Bus access to delete arbitrary files on the host filesystem by crafting a malicious URI. This issue is rated as MEDIUM with a CVSS score of 5.6. The vulnerability arises from inconsistent comparison logic in the addressbook file backend, which enables a Flatpak application to potentially delete critical system files, elevate privileges, and compromise sensitive data. Defenders responsible for managing evolution-data-server installations, especially in environments with untrusted Flatpak applications, should assess exposure and prioritize patching.
- Vendor
- GNOME
- Product
- evolution-data-server
- CVSS
- MEDIUM 5.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-09-25
Who should care
Defenders responsible for managing evolution-data-server installations, especially in environments with untrusted Flatpak applications, should assess exposure and prioritize patching.
Why it matters
The CVE-2026-2604 flaw in evolution-data-server allows a Flatpak application with D-Bus access to delete arbitrary files on the host filesystem. Defenders should prioritize verifying and patching evolution-data-server installations, especially in environments with untrusted Flatpak applications, to prevent potential elevation of privileges and compromise of sensitive data.
- Potential deletion of critical system files
- Elevation of privileges for untrusted Flatpak applications
- Compromise of sensitive data through file deletion
- Verification of evolution-data-server installations and patches
Technical summary
The evolution-data-server flaw allows a Flatpak application with D-Bus access to craft a malicious URI, potentially leading to the deletion of arbitrary files on the host filesystem. This occurs due to inconsistent comparison logic in the addressbook file backend. The URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, enabling the deletion of critical system files. Defenders should prioritize verifying and patching evolution-data-server installations, especially in environments with untrusted Flatpak applications.
Defensive priority
Defenders should prioritize verifying and patching evolution-data-server installations, especially in environments with untrusted Flatpak applications.
Recommended defensive actions
- Verify and apply patches for evolution-data-server
- Restrict D-Bus access for untrusted Flatpak applications
- Monitor for suspicious activity related to contact creation and deletion
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the flaw in evolution-data-server, including its CVSS score and potential impact. The flaw allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. The source detail is limited, so defenders should focus
Sources and references
Verified primary and authoritative sources
-
CVE-2026-2604 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-2604
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-2604 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-2604
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-2604
-
Source reference
Unverified legacy reference
URL: https://gitlab.gnome.org/GNOME/evolution-data-server/-/issues/627
-
Source reference
Unverified legacy reference
URL: https://lists.debian.org/debian-lts-announce/2026/03/msg00007.html
af854a3a-2127-422b-91ae-364da2661108
-
Source reference
Unverified legacy reference
URL: https://lists.debian.org/debian-lts-announce/2026/09/msg00031.html
af854a3a-2127-422b-91ae-364da2661108
-
Source reference
Unverified legacy reference
URL: https://gitlab.gnome.org/GNOME/evolution-data-server/-/work_items/627
134c704f-9b21-4f2e-91b3-4a467353bcc0
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.