Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-1225

Gravedad CVSS v4.0:
BAJA
Tipo:
CWE-20 Validación incorrecta de entrada
Fecha de publicación:
22/01/2026
Última modificación:
22/01/2026

Descripción

*** Pendiente de traducción *** ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file.<br /> <br /> <br /> <br /> <br /> The instantiation of a potentially malicious Java class requires that said class is present on the user&amp;#39;s class-path. In addition, the attacker must have write access to a <br /> configuration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado.

Referencias a soluciones, herramientas e información