vulnerabilityCVE-2026-104721
CVE-2026-104721
A flaw was found in logback-classic. This path traversal vulnerability allows a remote attacker to create and append log files outside the intended directory. The issue occurs when an unsanitized Mapped Diagnostic Context (MDC) discriminator value flows into a nested log file path, enabling an attacker who can influence this context, such as through an HTTP request header, to manipulate the destination file location.
Exploitation evidence
None confirmed
Affected software
| Software | Affected versions | Fixed in | Sources |
|---|---|---|---|
CVSS (Common Vulnerability Scoring System)
Preferred assessment
Vector
Attack vector
Attack complexity
Privileges required
User interaction
Scope
Confidentiality impact
Integrity impact
Availability impact
Source assessments
EPSS (Exploit Prediction Scoring System)
Probability
Percentile
Model
Preferred remediation
Action