Path Traversal Vulnerability in QOS.CH Logback-classic for Java
CVE-2026-19880

6.3MEDIUM

Key Information:

Vendor
CVE Published:
14 August 2026

Badges

👾 Exploit Exists

What is CVE-2026-19880?

The Logback-classic library, maintained by QOS.CH, has a path traversal vulnerability that can be exploited through an unsanitized MDC-based discriminator value. This can enable attackers to influence the nested FileAppender path, allowing the creation and appending of log files to unauthorized directories. The vulnerability affects all stable releases from 0.9.14 to 1.6.2, highlighting the need for careful handling of user inputs to prevent such security breaches.

Affected Version(s)

Logback-classic Java 0.9.14 <= 1.6.2

Logback-classic Java 0.9.14 <= 1.6.2

Logback-classic Java 1.6.3

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

York Shen - Yong Shen - PayPal Cyber Security Team (UID 100171)
.