6.3
MEDIUM CVSS 4.0
CVE-2026-104721
Logback: Incomplete protection against CVE-2026-19880
Description

Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender path, letting an attacker who influences that MDC value (e.g. via an HTTP header) create and append log files outside the intended directory. This issue affects Logback-classic: from 0.9.14 through 1.6.4.  This vulnerability is similar to CVE-2026-19880 but involves other attack techniques.

INFO

Published Date :

Oct. 2, 2026, 1:21 p.m.

Last Modified :

Oct. 2, 2026, 1:21 p.m.

Remotely Exploit :

Yes !

Source :

NCSC.ch
Affected Products

The following products are affected by CVE-2026-104721 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

No affected product recoded yet

CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 4.0 MEDIUM 455daabc-a392-441d-aa46-37d35189897c
Solution
Update Logback-classic to a version that addresses path traversal. Implement proper input sanitization for MDC values.
  • Update Logback-classic to version 1.6.5 or later.
  • Sanitize MDC values before using them in file paths.
  • Restrict access to log directories.
  • Monitor log file creation activities.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-104721 vulnerability anywhere in the article.

EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.