CVE-2026-88859
Public on 2026-09-10
Modified on 2026-09-11
Description
A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript handler incorrectly assigns an attacker-controlled JavaScript URL to an iframe's source. This action leads to arbitrary JavaScript execution within the mail-viewing context, effectively bypassing the security measures designed to prevent script execution in email content.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | evolution | Not Affected | ||
| Amazon Linux 2 - Core | evolution-data-server | Not Affected | ||
| Amazon Linux 2023 | evolution-data-server | Not Affected | ||
| Amazon Linux 2027 Preview | evolution-data-server | Not Affected | ||
| Amazon Linux 2 - Core | evolution-ews | Not Affected | ||
| Amazon Linux 2 - Core | evolution-mapi | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 5.3 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L |