CVE-2026-104721
Received Received - Intake

Path Traversal in Logback-classic Java Module

Vulnerability report for CVE-2026-104721, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Switzerland Government Common Vulnerability Program

Description

Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender path, letting an attacker who influences that MDC value (e.g. via an HTTP header) create and append log files outside the intended directory. This issue affects Logback-classic: from 0.9.14 through 1.6.4.Β  This vulnerability is similar to CVE-2026-19880 but involves other attack techniques.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
qos_ch_sarl logback_classic From 0.9.14 (inc) to 1.6.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java. It occurs when an MDC-based discriminator value is unsanitized and flows into a nested FileAppender path. An attacker can influence this value, such as via an HTTP header, to create and append log files outside the intended directory.

Detection Guidance

To detect this vulnerability, inspect logback-classic configurations for FileAppender paths that use MDC values unsanitized. Check for log files created outside intended directories, especially those influenced by HTTP headers like MDC values. Review logs for suspicious file writes or path-traversal patterns in logback.xml or similar files.

Impact Analysis

An attacker could write malicious log files to arbitrary locations on the system. This may lead to denial of service, unauthorized data access, or further exploitation if logs are processed by other systems. It could also allow attackers to overwrite critical files.

Compliance Impact

This vulnerability may violate compliance requirements by allowing unauthorized file access or modification. GDPR requires protecting personal data integrity, while HIPAA mandates secure handling of health information. Unauthorized log file manipulation could lead to data breaches or non-compliance.

Mitigation Strategies

Upgrade Logback-classic to a version beyond 1.6.4 to address the path-traversal vulnerability. Review MDC-based discriminator values in FileAppender configurations to ensure they are properly sanitized.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104721. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart