What is CVE-2026-19880?
CVE-2026-19880 is a path-traversal vulnerability in the QOS.CH Sarl Logback-classic module for Java. An unsanitized MDC-based discriminator value flows into a nested FileAppender path, potentially allowing an attacker who controls that MDC value to perform unauthorized file system access. Restricting input that influences MDC values is recommended.
Azərbaycanca: CVE-2026-19880, QOS.CH Sarl Logback-classic (Java) modulunda path-traversal zəifliyidir. MDC dəyəri vasitəsilə ötürülən təmizlənməmiş məlumat FileAppender yoluna daxil olur və təsir edən şəxs fayl sisteminə icazəsiz giriş əldə edə bilər. MDC dəyərlərini idarə edən giriş nöqtələrini məhdudlaşdırmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
In which library was CVE-2026-19880 discovered, and how is it exploited?
The vulnerability was identified in the QOS.CH Sarl Logback-classic (Java) module. An unsanitized MDC-based discriminator value flows into a nested FileAppender path, allowing an attacker who controls that MDC value to gain unauthorized file system access via a path-traversal attack.
What mitigation is recommended for CVE-2026-19880?
Restricting input that influences MDC values is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.