PT-2026-44381 · Logback · Logback

·

CVE-2026-9828

·

Published

2026-05-28

·

Updated

2026-06-12

CVSS v4.0

2.9

Low

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/RE:L/U:Green
Name of the Vulnerable Software and Affected Versions logback versions prior to 1.5.33
Description Deserialization of untrusted data in the HardenedObjectInputStream module of logback-core allows for restricted Object Injection. An attacker capable of influencing serialized data sent to the 'SimpleSocketServer' or 'SimpleSSLSocketServer' endpoints can instantiate objects from the java.lang and java.util packages that are not explicitly blocked. This issue represents a bypass of intended security restrictions, although no practical method for remote code execution or significant privilege escalation has been identified.
Recommendations Update to a version later than 1.5.32.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9828
GHSA-P47F-322F-WHFH
OPENSUSE-SU-2026:11016-1

Affected Products

Logback