Path Traversal Vulnerability in Cisco Jabber for Android
CVE-2026-101886
5.1MEDIUM
What is CVE-2026-101886?
Cisco Jabber for Android prior to version 15.3.1.311364 is susceptible to a path traversal vulnerability, enabling malicious applications to write unauthorized files into Jabber's private data directories. This exploitation occurs through the application’s exported activity 'crosslaunch.share' and an unsanitized display name extracted from a ContentProvider, which can be manipulated to include '../' sequences. Consequently, attackers can craft malicious content using a specially formatted content:// URI, gaining access to sensitive directories such as databases/, shared_prefs/, no_backup/, and files/ without any user interaction.
Affected Version(s)
Jabber for Android 0 < 15.3.1.311364