---
id: CVE-2026-104721
title: >-
  Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java
  (logback-classic module) allows path-traversal vulnerability
summary: >-
  Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java
  (logback-classic module) allows path-traversal vulnerability. More
  specifically, an 

  MDC-based discriminator value flows unsanitized into a nested 

  FileAppender path, le…
severity: medium
cvss: 6.3
cvssVector: >-
  CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/S:P/AU:N/RE:M/U:Green
cwe:
  - CWE-22
vendor: QOS.CH Sarl
product: Logback-classic
affected:
  - Logback-classic >= 0.9.14 <= 1.6.4
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T14:17:10.167'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104721'
references:
  - url: 'https://logback.qos.ch/news.html#1.6.5'
    label: vulnerability@ncsc.ch
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-02T14:20:32.572Z'
---

## Overview

Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an 
MDC-based discriminator value flows unsanitized into a nested 
FileAppender path, letting an attacker who influences that MDC value 
(e.g. via an HTTP header)
 create and append log files outside the intended directory. 


This issue affects Logback-classic: from 0.9.14 through 1.6.4.  This vulnerability is similar to CVE-2026-19880 but involves other attack techniques.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
