Path Traversal Vulnerability in Cisco Jabber for Android
CVE-2026-101886

5.1MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
7 October 2026

What is CVE-2026-101886?

Cisco Jabber for Android prior to version 15.3.1.311364 is susceptible to a path traversal vulnerability, enabling malicious applications to write unauthorized files into Jabber's private data directories. This exploitation occurs through the application’s exported activity 'crosslaunch.share' and an unsanitized display name extracted from a ContentProvider, which can be manipulated to include '../' sequences. Consequently, attackers can craft malicious content using a specially formatted content:// URI, gaining access to sensitive directories such as databases/, shared_prefs/, no_backup/, and files/ without any user interaction.

Affected Version(s)

Jabber for Android 0 < 15.3.1.311364

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Edward "Actuator" Warren
VulnCheck
.