AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-19880

MEDIUM · CVSS 6.3

Source: NVD + CISA KEV + EPSS · Published 2026-08-14 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The Logback-classic module in Java is vulnerable to a path-traversal issue that allows attackers to manipulate the MDC-based discriminator value, potentially enabling them to create and append log files outside the designated directory. This could lead to unauthorized access to sensitive information or system compromise. Organizations using affected versions (0.9.14 to 1.6.2) should prioritize patching this vulnerability to mitigate risks associated with log file exposure.

CVE
CVE-2026-19880
Severity
MEDIUM
CVSS
6.3
EPSS
N/A
Java

Original NVD Description

Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender path, letting an attacker who influences that MDC value (e.g. via an HTTP header) create and append log files outside the intended directory. This issue affects Logback-classic: from 0.9.14 through 1.6.2.