CVE 1.8 LOW

Malicious logback.xml configuration file allows instantiation of arbitrary classes_CVE-2026-1225

1.8 / 10
LOW
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/S:N/AU:N/RE:M/U:Green

Description

ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file.




The instantiation of a potentially malicious Java class requires that said class is present on the user's class-path. In addition, the attacker must have write access to a
configuration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado.

Basic Information

ID CVE-2026-1225
Source NCSC.ch
Published Jan 22, 2026 at 09:24
Modified Jan 22, 2026 at 14:14

Affected Product

Vendor QOS.CH Sarl
Product Logback-core
Version 0.9.20
Affected Versions QOS.CH Sarl Logback-core 0.9.20

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.