Critical severity9.9NVD Advisory· Published Jul 29, 2026· Updated Sep 10, 2026
CVE-2026-54680
CVE-2026-54680
Description
Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such as Flow record_transformer.records values directly into fluent.conf without escaping, allowing a user who can create Flow resources to inject a Fluentd block using @type exec and execute arbitrary commands inside the Fluentd aggregator. This issue is fixed in version 6.6.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/kube-logging/logging-operatorGo | < 0.0.0-20260608145523-cf437d7f1e05 | 0.0.0-20260608145523-cf437d7f1e05 |
Affected products
4- Range: <6.6.0
- osv-coords3 versionspkg:apk/chainguard/docker-machine-driver-harvesterpkg:apk/wolfi/docker-machine-driver-harvesterpkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0
< 0+ 2 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0.0.20260827T195228-160000.1.1
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.