Issue
A Nessus scan identified the Apache Log4j vulnerability, CVE-2026-49844, in the DWS component.
Solution
The Tungsten Development team has reviewed CVE-2026-49844 and confirmed DWS is not affected by the vulnerability.
About the log4j version, the Tungsten development team has created a fix to upgrade log4j to 2.26.1
The following libraries are now upgraded to version 2.26.1 to resolve the issue:
- log4j-core-2.17.2.jar
- log4j-api-2.17.2.jar
- log4j-1.2-api-2.17.2.jar
Applies to
| Product | Version |
|---|
| Control Suite | CS 1.5.2 |
References
ControlSuite Vulnerability Overview