CVE-2026-34478 | Apache Log4j Core up to 2.25.3/3.0.0-beta3 Configuration incorrect provision of specified functionality (Nessus ID 306185 / WID-SEC-2026-1067)
A vulnerability labeled as problematic has been found in Apache Log4j Core up to 2.25.3/3.0.0-beta3. This affects an unknown part of the component Configuration Handler. Executing a manipulation can lead to incorrect provision of specified functionality.
This vulnerability is tracked as CVE-2026-34478. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.