Critical severityNVD Advisory· Published Jul 29, 2026· Updated Jul 30, 2026
Logging operator has Fluentd configuration injection that allows remote code execution
CVE-2026-54680
Description
Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such as Flow record_transformer.records values directly into fluent.conf without escaping, allowing a user who can create Flow resources to inject a Fluentd block using @type exec and execute arbitrary commands inside the Fluentd aggregator. This issue is fixed in version 6.6.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/kube-logging/logging-operatorGo | < 0.0.0-20260608145523-cf437d7f1e05 | 0.0.0-20260608145523-cf437d7f1e05 |
Affected products
1- Range: <6.6.0
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-mjqf-28ph-426hghsaADVISORY
- github.com/kube-logging/logging-operator/commit/cf437d7f1e056c78740bf5716ac8bdebcf002425ghsax_refsource_MISCWEB
- github.com/kube-logging/logging-operator/releases/tag/6.6.0ghsax_refsource_MISCWEB
- github.com/kube-logging/logging-operator/security/advisories/GHSA-mjqf-28ph-426hghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.