Sceawere
Vulnerability Detail
CVE-2026-101886UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Cisco Jabber Path Traversal
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4
- Creation Date
- 1d ago
- Vendor
- Cisco
- Product
- Jabber for Android
- Attack Type
- Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Cisco Jabber for Android (com.cisco.im) before 15.3.1.311364 contains a path traversal vulnerability that allows a malicious app with no permissions to write attacker-controlled files into Jabber's private data directory by exploiting the exported crosslaunch.share activity and an unsanitized display name from a ContentProvider used in file path construction. Attackers can craft a shared content:// URI with a display name containing '../' sequences to place fully attacker-controlled content within directories such as databases/, shared_prefs/, no_backup/, and files/ without user interaction.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.0",
"pubDate": "2026-10-07T17:16:45.613Z",
"pubdate": "2026-10-07T17:16:45.613Z",
"executiveSummary": "Cisco Jabber for Android contains a critical path traversal vulnerability due to improper sanitization of file display names.\nThe vulnerability resides within the exported 'crosslaunch.share' activity, allowing a malicious application without specific privileges to perform arbitrary file writes.\nBy leveraging a crafted 'content://' URI, an attacker can bypass standard sandbox restrictions to inject files into the application's private data directory, including sensitive subdirectories such as 'databases/', 'shared_prefs/', 'no_backup/', and 'files/'.\nThis vulnerability requires no user interaction and can be exploited by an unprivileged third-party application already installed on the device.\nThe impact is significant, as it permits unauthorized modification of application configuration and data, potentially leading to full account takeover, session hijacking, or application compromise.\nThe affected product is Cisco Jabber for Android (com.cisco.im) with versions prior to 15.3.1.311364.",
"technicalDetails": "The vulnerability is rooted in an insecure implementation of an exported Android activity, 'crosslaunch.share', which acts as an entry point for external applications to initiate file sharing operations.\nThe underlying flaw exists because the application fails to adequately sanitize the 'display name' property retrieved from a 'ContentProvider'. This property is subsequently utilized in the construction of file paths within the internal storage of the 'com.cisco.im' package.\nAn attacker exploits this by creating a malicious application that triggers the 'crosslaunch.share' activity, passing a specially crafted 'content://' URI. The display name metadata embedded within this URI includes directory traversal sequences, such as '../', which escape the intended target directory and traverse into sensitive locations.\nBecause the application does not validate the integrity of the resulting path, it effectively instructs the system to write the attacker-provided content into protected subdirectories. These include, but are not limited to, 'databases/', 'shared_prefs/', 'no_backup/', and 'files/'.\nWriting to these directories allows the attacker to replace critical application configuration files (XML-based shared preferences) or inject malicious content into existing SQLite databases. For example, modifying 'shared_prefs/' could allow an attacker to alter authentication tokens or session settings, while modifying 'databases/' could enable data exfiltration or logic manipulation within the Jabber internal state.\nThe attack flow follows these steps: 1) The attacker constructs a 'content://' URI where the display name field is manipulated with '../' sequences. 2) The attacker's malicious application sends an intent to launch the 'crosslaunch.share' activity with the malicious URI as data. 3) The Cisco Jabber application, lacking sufficient sanitization checks, interprets the traversal sequences to resolve an absolute path outside the intended directory. 4) The application writes the attacker-controlled file to the sensitive location. 5) Subsequent execution or access by Cisco Jabber of the manipulated file results in malicious code execution or unintended application behavior.\nThis vulnerability is particularly severe because it does not require user interaction or escalated privileges on the device, as it leverages the trust model inherent in exported Android components.\nThe affected versions are all iterations of Cisco Jabber for Android prior to 15.3.1.311364."
}