CVE-2026-1225
Severity CVSS v4.0:
LOW
Type:
CWE-20
Input Validation
Publication date:
22/01/2026
Last modified:
22/01/2026
Description
ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file.<br />
<br />
<br />
<br />
<br />
The instantiation of a potentially malicious Java class requires that said class is present on the user&#39;s class-path. In addition, the attacker must have write access to a <br />
configuration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado.



