PT-2026-51676 · Janino+1 · Janino+1

·

CVE-2026-13006

·

Published

2026-06-24

·

Updated

2026-07-21

CVSS v4.0

7.0

High

VectorAV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:X/V:X/RE:M/U:Green
Name of the Vulnerable Software and Affected Versions logback-core versions prior to 1.5.35
Description An arbitrary code execution issue exists in the conditional configuration file processing of Java applications. An attacker can execute arbitrary code by compromising an existing logback configuration file or by injecting an environment variable before program execution, which bypasses protections against previous similar issues. This attack requires the Janino library to be present on the user's class path and requires the attacker to have existing privileges, such as write access to a configuration file or the ability to inject a malicious environment variable pointing to a malicious configuration file.
Recommendations Update to version 1.5.35 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-WT54034
CVE-2026-13006
OPENSUSE-SU-2026:11135-1

Affected Products

Janino
Logback-Core