MDC-based discriminator value flows unsanitized into a nested
FileAppender path, letting an attacker who influences that MDC value
(e.g. via an HTTP header)
create and append log files outside the intended directory.
This issue affects Logback-classic: from 0.9.14 through 1.6.4. This vulnerability is similar to CVE-2026-19880 but involves other attack techniques.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update to logack version 1.6.5 or later. This vulnerability requires SiftingAppender to be active as well as unsanitized data provided by an attacker that MDCDiscriminator makes use of. Sanitizing relevant data provided by the user should fix this vulnerability.
Vendor Workaround
Update to logack version 1.6.5 or later. This vulnerability requires SiftingAppender to be active as well as unsanitized data provided by an attacker that MDCDiscriminator makes use of.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://logback.qos.ch/news.html#1.6.5 |
|
Fri, 02 Oct 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender path, letting an attacker who influences that MDC value (e.g. via an HTTP header) create and append log files outside the intended directory. This issue affects Logback-classic: from 0.9.14 through 1.6.4. This vulnerability is similar to CVE-2026-19880 but involves other attack techniques. | |
| Title | Logback: Incomplete protection against CVE-2026-19880 | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: NCSC.ch
Published:
Updated: 2026-10-02T13:21:59.195Z
Reserved: 2026-10-02T11:43:59.014Z
Link: CVE-2026-104721
No data.
Status : Received
Published: 2026-10-02T14:17:10.167
Modified: 2026-10-02T14:17:10.167
Link: CVE-2026-104721
No data.
OpenCVE Enrichment
Updated: 2026-10-02T15:15:07Z