A vulnerability categorized as problematic has been discovered in Apache Log4cxx up to 1.6.x. Affected by this vulnerability is an unknown functionality. Such manipulation leads to escaping of output.

This vulnerability is referenced as CVE-2026-40023. It is possible to launch the attack remotely. No exploit is available.

It is advisable to upgrade the affected component.