CVE-2026-1225

LOW

logback-core <= 1.5.24 - Arbitrary Class Instantiation via Configuration File Processing

Title source: llm
STIX 2.1

Description

ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file. The instantiation of a potentially malicious Java class requires that said class is present on the user's class-path. In addition, the attacker must have write access to a configuration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado.

References (1)

Core 1
Core References

Scores

CVSS v4 1.8
EPSS 0.0015
EPSS Percentile 4.6%
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:X/V:X/RE:M/U:Green

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (1)
ch.qos.logback/logback-core 0 - 1.5.25Maven
Published Jan 22, 2026
Tracked Since Feb 18, 2026