Path Traversal Vulnerability in QOS.CH Logback-classic for Java
CVE-2026-19880
6.3MEDIUM
What is CVE-2026-19880?
The Logback-classic library, maintained by QOS.CH, has a path traversal vulnerability that can be exploited through an unsanitized MDC-based discriminator value. This can enable attackers to influence the nested FileAppender path, allowing the creation and appending of log files to unauthorized directories. The vulnerability affects all stable releases from 0.9.14 to 1.6.2, highlighting the need for careful handling of user inputs to prevent such security breaches.
Affected Version(s)
Logback-classic Java 0.9.14 <= 1.6.2
Logback-classic Java 0.9.14 <= 1.6.2
Logback-classic Java 1.6.3
References
CVSS V4
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
York Shen - Yong Shen - PayPal Cyber Security Team (UID 100171)
