PT-2026-104330 · Qos.Ch Sarl · Logback-Classic

·

CVE-2026-104721

·

Published

2026-10-02

·

Updated

2026-10-02

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/S:P/AU:N/RE:M/U:Green
Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender path, letting an attacker who influences that MDC value (e.g. via an HTTP header) create and append log files outside the intended directory.
This issue affects Logback-classic: from 0.9.14 through 1.6.4.  This vulnerability is similar to CVE-2026-19880 but involves other attack techniques.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104721

Affected Products

Logback-Classic