Impact of CVE-2026-49844 on Protection Engine
search cancel

Impact of CVE-2026-49844 on Protection Engine

book

Article ID: 450164

calendar_today

Updated On:

Products

Protection Engine for NAS

Issue/Introduction

Is Symantec Protection Engine (SPE) affected by  CVE-2026-49844?

Environment

SPE 9.3

Resolution

CVE-2026-49844: SPE is not impacted.

CVE-2026-49844 is a Medium-severity (CVSS 5.9) integrity vulnerability in Apache Log4j that allows a remote, unauthenticated attacker to inject malicious content into structured log output, however, only when following conditions are met:

  • The application is simultaneously configured to use a JSON-based log rendering layout AND
  • Actively logs structured message objects containing attacker-controlled values.

Both the conditions must hold at the same time for the vulnerable code path to be reached.

Because SPE exclusively employs pattern-based text layouts for its logging configuration, it does not utilize the structured message logging necessary to trigger this vulnerability. As neither precondition for exploitation is satisfied, SPE is not impacted.