CVE-2026-44024 is an improper pathname limitation vulnerability in Fluentd versions before 1.19.3. Fluentd dynamically expands the ${tag} placeholder in file-path configuration values, including the out_file output plugin path parameter. Insufficient validation permits attacker-controlled tags containing path-traversal sequences to escape the intended output directory and cause arbitrary file creation or overwrite. Depending on the writable locations, file content control, and Fluentd process privileges, the arbitrary write can be leveraged for remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
${tag} in file-path parameters for untrusted tags. Run Fluentd under a dedicated unprivileged account and constrain its filesystem permissions to only required output directories.Patch, then assume compromise.
${tag} and remove or redesign unsafe dynamic path expansion where tags can be influenced by untrusted event sources. Apply vendor-provided updated component releases for products that bundle Fluentd.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept exploit for CVE-2026-44024 affecting Fluentd out_file path templating. The repo contains only two files: a README explaining the vulnerability, prerequisites, and usage, and exploit.py implementing the attack. The exploit is not part of a larger framework. Core capability: it sends a minimally encoded Fluentd forward-protocol message over TCP to the target's in_forward listener, using a crafted tag value of ../../../../../../etc/cron.d/pwn. Because vulnerable Fluentd versions substitute ${tag} into out_file paths without sanitizing ../ components, the attacker can escape the intended log directory and write to an arbitrary filesystem path as the Fluentd process user. The provided exploit specifically targets /etc/cron.d/pwn and writes a cron line containing either an operator-supplied command or a bash reverse shell, yielding code execution. Implementation details: exploit.py includes a tiny built-in MessagePack encoder supporting only the types needed for a Fluentd message ([tag, time, record]) and uses socket.create_connection to send the packet. The script accepts a target host[:port], defaults to TCP/24224, and supports either --cmd for blind command execution or --shell HOST:PORT for a reverse shell payload. The reverse shell is hardcoded as a bash /dev/tcp one-liner. Operational assumptions: exploitation requires a vulnerable Fluentd deployment (<= 1.19.2), an out_file path containing ${tag}, and a reachable in_forward input that accepts attacker-controlled events. The demonstrated RCE path further assumes output formatting that preserves the msg field as a valid cron line and sufficient privileges for Fluentd to write into /etc/cron.d. The README also notes that in_http on port 9880 is not a viable vector because path handling converts slashes to dots, preventing ../ traversal.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
High-severity unauthenticated HTTP vulnerability in the Fluentd component of Oracle Communications Unified Assurance.
A vulnerability affecting VMware PhotonOS 5.0 rubygem packages, referenced in PhotonOS advisory PHSA-2026-5.0-91-0960.
A critical Fluentd vulnerability that allows arbitrary file write via path traversal in the ${tag} placeholder, potentially leading to remote code execution.
A high-severity Fluentd vulnerability that can lead to remote code execution via improper handling of the ${tag} placeholder, enabling arbitrary file writes and possible full system compromise.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.