CVE-2026-101886
Received Received - Intake

Path Traversal in Cisco Jabber for Android

Vulnerability report for CVE-2026-101886, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: VulnCheck

Description

Cisco Jabber for Android (com.cisco.im) before 15.3.1.311364 contains a path traversal vulnerability that allows a malicious app with no permissions to write attacker-controlled files into Jabber's private data directory by exploiting the exported crosslaunch.share activity and an unsanitized display name from a ContentProvider used in file path construction. Attackers can craft a shared content:// URI with a display name containing '../' sequences to place fully attacker-controlled content within directories such as databases/, shared_prefs/, no_backup/, and files/ without user interaction.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Cisco Jabber for Android 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Cisco Jabber for Android before version 15.3.1.311364 has a path traversal vulnerability. A malicious app with no permissions can write attacker-controlled files into Jabber's private data directory by exploiting an exported activity and an unsanitized display name from a ContentProvider. Attackers craft a shared content URI with '../' sequences to place files in directories like databases, shared_prefs, no_backup, and files without user interaction.

Detection Guidance

Check if Cisco Jabber for Android is installed and verify the version. If it is below 15.3.1.311364, the device is vulnerable. Inspect installed apps for suspicious permissions or activities like crosslaunch.share.

Impact Analysis

This vulnerability allows attackers to place malicious files in sensitive directories of Cisco Jabber for Android. This could lead to data theft, app crashes, or unauthorized access to stored information like messages or preferences. Since no user interaction is required, the risk is high for users with the vulnerable app installed.

Mitigation Strategies

Update Cisco Jabber for Android to version 15.3.1.311364 or later immediately. Remove or disable the app if an update is not available. Monitor for unusual file writes in Jabber's private directories like databases/ or shared_prefs/.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101886. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart