CVE-2026-101886

Cisco Jabber for Android Path Traversal via Shared Content URI

Severity
Medium 5.1
CVSS 4.0
Adjacent, local or physical access what this means
Exploited
Not listed
EPSS
—
Discovered by
Unknown
Vendor-published field
Published
Oct 7, 2026
Assigned by vulncheck

Description

Cisco Jabber for Android (com.cisco.im) before 15.3.1.311364 contains a path traversal vulnerability that allows a malicious app with no permissions to write attacker-controlled files into Jabber's private data directory by exploiting the exported crosslaunch.share activity and an unsanitized display name from a ContentProvider used in file path construction. Attackers can craft a shared content:// URI with a display name containing '../' sequences to place fully attacker-controlled content within directories such as databases/, shared_prefs/, no_backup/, and files/ without user interaction.

Weakness: CWE-22

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported products (1)
  • Cisco · Jabber for Android

Credit

Edward "Actuator" Warren

Something wrong here?