CRITICAL
kube-logging
CVE published 2026-07-29
CVE-2026-54680
CVE-2026-54680 is a critical vulnerability in the Logging operator for Kubernetes, allowing users with permission to create Flow resources to inject arbitrary commands into the Fluentd aggregator. This issue, fixed in version 6.6.0, has a CVSS score of 9.9 and requires immediate attention from defenders. The vulnerability exists in the Fluentd configuration renderer FluentRender, which writes CRD strings [truncated]