CVE-2026-54680 | kube-logging logging-operator up to 6.5.99 Fluentd configuration renderer fluent.go FluentRender record_transformer.records os command injection

SecurityVulns

A vulnerability, which was classified as very critical, was found in kube-logging logging-operator up to 6.5.99. Affected is the function FluentRender of the file pkg/sdk/logging/model/render/fluent.go of the component Fluentd configuration renderer. Such manipulation of the argument record_transformer.records leads to os command injection.

This vulnerability is listed as CVE-2026-54680. The attack may be performed from remote. There is no available exploit.

You should upgrade the affected component.VulDB Recent EntriesRead More