ZERO
Back
vulnerabilityCVE-2026-104721

CVE-2026-104721

A flaw was found in logback-classic. This path traversal vulnerability allows a remote attacker to create and append log files outside the intended directory. The issue occurs when an unsanitized Mapped Diagnostic Context (MDC) discriminator value flows into a nested log file path, enabling an attacker who can influence this context, such as through an HTTP request header, to manipulate the destination file location.

Exploitation evidence
None confirmed

Affected software

CVSS (Common Vulnerability Scoring System)

Preferred assessment

Vector

Attack vector

Attack complexity

Privileges required

User interaction

Scope

Confidentiality impact

Integrity impact

Availability impact

Source assessments

EPSS (Exploit Prediction Scoring System)

Probability

Percentile

Model

Preferred remediation

Action