A high-severity flaw tracked as CVE-2026-54680 allows remote code execution in the kube-logging/logging-operator before version 6.6.0 by injecting malicious content into generated Fluentd configuration. The bug is in the FluentRender component, which writes CRD-supplied strings directly into fluent.conf without properly escaping special characters. Attackers with permission to create Flow or ClusterFlow resources can abuse fields such as record_transformer.records to break out of nested configuration blocks and insert arbitrary top-level Fluentd directives.
By injecting a crafted <match **> block and using plugins such as @type exec, an attacker can execute arbitrary commands inside the Fluentd aggregator when logs are processed. The vulnerability is classified as command injection and configuration injection, mapped to CWE-77 and CWE-74, with CVSS v3.1 AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Maintainers fixed the issue in logging-operator 6.6.0 by escaping newline, carriage return, tab, quote, backslash, and # characters, while defenders were also provided a Kyverno policy example to block newline characters in vulnerable record fields as a mitigation.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-54680 was publicly described as a Fluentd configuration injection vulnerability in logging-operator's FluentRender component. The disclosure states that an attacker able to create Flow resources can inject a Fluentd <match **> block using @type exec and execute arbitrary commands inside the Fluentd aggregator.
A command injection vulnerability in kube-logging logging-operator affecting versions earlier than 6.6.0 was fixed in version 6.6.0. The patch escapes special characters in Fluentd configuration rendering to prevent CRD-supplied values from injecting arbitrary Fluentd directives and achieving remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.