CVE-2026-54680 | kube-logging logging-operator up to 6.5.99 Fluentd configuration renderer fluent.go FluentRender record_transformer.records os command injection
A vulnerability, which was classified as very critical, was found in kube-logging logging-operator up to 6.5.99. Affected is the function FluentRender of the file pkg/sdk/logging/model/render/fluent.go of the component Fluentd configuration renderer. Such manipulation of the argument record_transformer.records leads to os command injection.
This vulnerability is listed as CVE-2026-54680. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.VulDB Recent EntriesRead More