Medium severity4.0NVD Advisory· Published Oct 7, 2026
CVE-2026-101886
CVE-2026-101886
Description
Cisco Jabber for Android (com.cisco.im) before 15.3.1.311364 contains a path traversal vulnerability that allows a malicious app with no permissions to write attacker-controlled files into Jabber's private data directory by exploiting the exported crosslaunch.share activity and an unsanitized display name from a ContentProvider used in file path construction. Attackers can craft a shared content:// URI with a display name containing '../' sequences to place fully attacker-controlled content within directories such as databases/, shared_prefs/, no_backup/, and files/ without user interaction.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <15.3.1.311364
- Range: <15.3.1.311364
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.