What is CVE-2026-54680?
CVE-2026-54680: In Logging operator versions prior to 6.6.0, the `FluentRender` function in `pkg/sdk/logging/model/render/fluent.go` directly writes CRD strings such as Flow `record_transformer.records` values into `fluent.conf` without proper sanitization. Users of Kubernetes logging pipelines must upgrade immediately and audit their configuration files.
Azərbaycanca: CVE-2026-54680: Logging operator-un 6.6.0-dən əvvəlki versiyalarında `FluentRender` funksiyası Flow record_transformer.records kimi CRD stringlərini `fluent.conf` faylına birbaşa yazaraq təhlükəsizlik boşluğu yaradır. Kubernetes logging pipeline istifadəçiləri dərhal ən son versiyaya yeniləməli, konfiqurasiya fayllarını yoxlamalıdır.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which versions of Logging operator are affected by CVE-2026-54680?
This vulnerability affects versions of Logging operator prior to 6.6.0.
What should Kubernetes logging pipeline users do to mitigate CVE-2026-54680?
Users must upgrade immediately to the latest version and audit their configuration files.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.