CVE-2026-19880: Incomplete protection against CVE-2025-11226
Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender path, letting an attacker who influences that MDC value (e.g. via an HTTP header) create and append log files outside the intended directory.
This issue affects Logback-classic: from 0.9.14 through 1.6.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
logback-classicto a version that resolves this vulnerability.Fixed in 1.6.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19880?
CVE-2026-19880 has a risk score of 43, indicating a moderate severity level.
How do I fix CVE-2026-19880?
To mitigate CVE-2026-19880, update to a patched version of QOS.CH Logback-classic that addresses this vulnerability.
What systems are affected by CVE-2026-19880?
CVE-2026-19880 affects systems utilizing the QOS.CH Logback-classic library, specifically within the FileAppender implementation.
What type of vulnerability is CVE-2026-19880?
CVE-2026-19880 is a path-traversal vulnerability that can lead to unauthorized file access.
Can CVE-2026-19880 be exploited remotely?
Yes, CVE-2026-19880 can potentially be exploited remotely if an attacker can influence the MDC-based discriminator value.