Path traversal in GNOME Evolution Data Server - CVE-2026-2604

 

Path traversal in GNOME Evolution Data Server - CVE-2026-2604

Published: February 24, 2026


Vulnerability identifier: #VU123164
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-2604
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to delete arbitrary files on the system.

The vulnerability exists due to input validation error when processing directory traversal sequences in vCards within the maybe_delete_uri() function in src/addressbook/backends/file/e-book-backend-file.c. A remote user can pass specially crafted file path to the application containing directory traversal characters and delete arbitrary files on the system. 


Affected software

GNOME Evolution Data Server
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Workstation Extension 15
SUSE Package Hub 15
openSUSE Leap
Ubuntu
openEuler
evolution-data-server (Ubuntu package)
evolution-data-server
evolution-data-server-debuginfo
evolution-data-server-debugsource
evolution-data-server-devel
evolution-data-server-perl
evolution-data-server-langpacks
evolution-data-server-doc
typelib-1_0-EDataServer-1_2
typelib-1_0-EDataServerUI-1_2
libedataserver-1_2-26-debuginfo
libcamel-1_2-63
libedata-cal-2_0-1
libebook-1_2-20
libebook-1_2-20-debuginfo
libebackend-1_2-10
typelib-1_0-EBookContacts-1_2
libebook-contacts-1_2-3
libedata-book-1_2-26
typelib-1_0-Camel-1_2
libebook-contacts-1_2-3-debuginfo
typelib-1_0-ECal-2_0
libedata-cal-2_0-1-debuginfo
typelib-1_0-EDataCal-2_0
libedataserverui-1_2-3-debuginfo
libedata-book-1_2-26-debuginfo
libecal-2_0-1-debuginfo
libedataserver-1_2-26
typelib-1_0-EDataBook-1_2
libcamel-1_2-63-debuginfo
evolution-data-server-lang
libedataserverui-1_2-3
typelib-1_0-EBackend-1_2
libecal-2_0-1
libebackend-1_2-10-debuginfo
typelib-1_0-EBook-1_2
evolution-data-server-help
libebook-1_2-21-debuginfo
libebook-1_2-21
libebook-contacts-1_2-4
libedata-cal-2_0-2-debuginfo
libcamel-1_2-64
libedata-book-1_2-27
libecal-2_0-2-debuginfo
libedataserverui-1_2-4
libedataserverui4-1_0-0
typelib-1_0-EDataServerUI4-1_0
libedataserver-1_2-27
libebook-contacts-1_2-4-debuginfo
libebackend-1_2-11
libebackend-1_2-11-debuginfo
libedataserverui-1_2-4-debuginfo
libedataserver-1_2-27-debuginfo
libedataserverui4-1_0-0-debuginfo
libcamel-1_2-64-debuginfo
libedata-cal-2_0-2
libecal-2_0-2
libedata-book-1_2-27-debuginfo

How to mitigate CVE-2026-2604

Install update from vendor's repository.

evolution-data-server (Ubuntu package) - addressed in versions 3.28.5-0ubuntu0.18.04.3+esm1, 3.36.5-0ubuntu1+esm1, 3.44.4-0ubuntu1.2, 3.52.3-0ubuntu1.2, 3.56.2-3ubuntu0.1
evolution-data-server - addressed in versions 3.30.1-7, 3.38.4-4, 3.46.2-3
evolution-data-server-debuginfo - addressed in versions 3.30.1-7, 3.38.4-4, 3.46.2-3
evolution-data-server-debugsource - addressed in versions 3.30.1-7, 3.38.4-4, 3.46.2-3
evolution-data-server-devel - addressed in versions 3.30.1-7, 3.38.4-4, 3.46.2-3
evolution-data-server-perl - addressed in versions 3.30.1-7, 3.38.4-4, 3.46.2-3
evolution-data-server-langpacks - addressed in versions 3.30.1-7, 3.38.4-4, 3.46.2-3
evolution-data-server-doc - addressed in versions 3.30.1-7, 3.38.4-4
typelib-1_0-EDataServer-1_2 - addressed in versions 3.42.5-150400.3.10.1, 3.50.3-150600.3.9.1
typelib-1_0-EDataServerUI-1_2 - addressed in versions 3.42.5-150400.3.10.1, 3.50.3-150600.3.9.1
libedataserver-1_2-26-debuginfo - update to 3.42.5-150400.3.10.1
libcamel-1_2-63 - update to 3.42.5-150400.3.10.1
libedata-cal-2_0-1 - update to 3.42.5-150400.3.10.1
libebook-1_2-20 - update to 3.42.5-150400.3.10.1
libebook-1_2-20-debuginfo - update to 3.42.5-150400.3.10.1
libebackend-1_2-10 - update to 3.42.5-150400.3.10.1
typelib-1_0-EBookContacts-1_2 - addressed in versions 3.42.5-150400.3.10.1, 3.50.3-150600.3.9.1
libebook-contacts-1_2-3 - update to 3.42.5-150400.3.10.1
libedata-book-1_2-26 - update to 3.42.5-150400.3.10.1
typelib-1_0-Camel-1_2 - addressed in versions 3.42.5-150400.3.10.1, 3.50.3-150600.3.9.1
evolution-data-server-devel - addressed in versions 3.42.5-150400.3.10.1, 3.50.3-150600.3.9.1
libebook-contacts-1_2-3-debuginfo - update to 3.42.5-150400.3.10.1
typelib-1_0-ECal-2_0 - addressed in versions 3.42.5-150400.3.10.1, 3.50.3-150600.3.9.1
libedata-cal-2_0-1-debuginfo - update to 3.42.5-150400.3.10.1
typelib-1_0-EDataCal-2_0 - addressed in versions 3.42.5-150400.3.10.1, 3.50.3-150600.3.9.1
evolution-data-server-debuginfo - addressed in versions 3.42.5-150400.3.10.1, 3.50.3-150600.3.9.1
libedataserverui-1_2-3-debuginfo - update to 3.42.5-150400.3.10.1
libedata-book-1_2-26-debuginfo - update to 3.42.5-150400.3.10.1
libecal-2_0-1-debuginfo - update to 3.42.5-150400.3.10.1
libedataserver-1_2-26 - update to 3.42.5-150400.3.10.1
evolution-data-server - addressed in versions 3.42.5-150400.3.10.1, 3.50.3-150600.3.9.1
typelib-1_0-EDataBook-1_2 - addressed in versions 3.42.5-150400.3.10.1, 3.50.3-150600.3.9.1
evolution-data-server-debugsource - addressed in versions 3.42.5-150400.3.10.1, 3.50.3-150600.3.9.1
libcamel-1_2-63-debuginfo - update to 3.42.5-150400.3.10.1
evolution-data-server-lang - addressed in versions 3.42.5-150400.3.10.1, 3.50.3-150600.3.9.1
libedataserverui-1_2-3 - update to 3.42.5-150400.3.10.1
typelib-1_0-EBackend-1_2 - addressed in versions 3.42.5-150400.3.10.1, 3.50.3-150600.3.9.1
libecal-2_0-1 - update to 3.42.5-150400.3.10.1
libebackend-1_2-10-debuginfo - update to 3.42.5-150400.3.10.1
typelib-1_0-EBook-1_2 - addressed in versions 3.42.5-150400.3.10.1, 3.50.3-150600.3.9.1
evolution-data-server-help - update to 3.46.2-3
libebook-1_2-21-debuginfo - update to 3.50.3-150600.3.9.1
libebook-1_2-21 - update to 3.50.3-150600.3.9.1
libebook-contacts-1_2-4 - update to 3.50.3-150600.3.9.1
libedata-cal-2_0-2-debuginfo - update to 3.50.3-150600.3.9.1
libcamel-1_2-64 - update to 3.50.3-150600.3.9.1
libedata-book-1_2-27 - update to 3.50.3-150600.3.9.1
libecal-2_0-2-debuginfo - update to 3.50.3-150600.3.9.1
libedataserverui-1_2-4 - update to 3.50.3-150600.3.9.1
libedataserverui4-1_0-0 - update to 3.50.3-150600.3.9.1
typelib-1_0-EDataServerUI4-1_0 - update to 3.50.3-150600.3.9.1
libedataserver-1_2-27 - update to 3.50.3-150600.3.9.1
libebook-contacts-1_2-4-debuginfo - update to 3.50.3-150600.3.9.1
libebackend-1_2-11 - update to 3.50.3-150600.3.9.1
libebackend-1_2-11-debuginfo - update to 3.50.3-150600.3.9.1
libedataserverui-1_2-4-debuginfo - update to 3.50.3-150600.3.9.1
libedataserver-1_2-27-debuginfo - update to 3.50.3-150600.3.9.1
libedataserverui4-1_0-0-debuginfo - update to 3.50.3-150600.3.9.1
libcamel-1_2-64-debuginfo - update to 3.50.3-150600.3.9.1
libedata-cal-2_0-2 - update to 3.50.3-150600.3.9.1
libecal-2_0-2 - update to 3.50.3-150600.3.9.1
libedata-book-1_2-27-debuginfo - update to 3.50.3-150600.3.9.1

External References

Related Security Bulletins