CVE-2026-44024Patch(fluentd / fluentd)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch fluentd fluentd systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd allows dynamically constructing file paths using the ${tag} placeholder, and insufficient validation of ${tag} in file configurations such as the path parameter of the out_file plugin allows attackers sending untrusted tags containing path traversal characters to write or overwrite arbitrary files and potentially achieve remote code execution. This issue is fixed in version 1.19.3.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fluentd

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 9 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-07-01); latest day: 1
  • 10 total mentions across 9 days

Affected systems

Vendors
Products
fluentd

Deep dive

Activity timeline10 mentions / 9d
01122Mentions · 2026-06-26: 1Mentions · 2026-06-27: 1Mentions · 2026-06-29: 1Mentions · 2026-06-30: 1Mentions · 2026-07-01: 2Mentions · 2026-07-09: 1Mentions · 2026-07-13: 1Mentions · 2026-07-14: 1Mentions · 2026-07-23: 1Patch / Workaround · 2026-06-27: 1Patch / Workaround · 2026-06-30: 1Patch / Workaround · 2026-07-01: 2Patch / Workaround · 2026-07-13: 1Patch / Workaround · 2026-07-14: 1Technical Details · 2026-06-26: 1Technical Details · 2026-06-27: 1Technical Details · 2026-06-30: 1Technical Details · 2026-07-01: 2Technical Details · 2026-07-09: 1Technical Details · 2026-07-13: 1Technical Details · 2026-07-14: 1Technical Details · 2026-07-23: 106-2606-2706-2906-3007-0107-0907-1307-1407-23
Signal classification3 categories
Patch
550.0%
Disclosure
440.0%
General
110.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-06-261
Disclosure1
2026-06-271
Disclosure1
2026-06-291
General1
2026-06-301
Patch1
2026-07-012
Patch2
2026-07-091
Disclosure1
2026-07-131
Patch1
2026-07-141
Patch1
2026-07-231
Disclosure1
Full discourse10 posts
  • Wazuh@wazuh
    Patch

    Fluentd is affected by CVE-2026-44024 (CVSS 9.8 - Critical), a path traversal flaw that may allow arbitrary file write and potential RCE via crafted ${tag} values. Upgrade to 1.19.3 or later. Read more: https://ow.ly/INPy50ZniN9 https://t.co/kOSAzFT7yi

    Post summary

    Fluentd suffers a critical path‑traversal flaw (CVE‑2026‑44024) that permits arbitrary file writes and potential RCE; updating to version 1.19.3 or later mitigates the issue.

    05090895
    8.2K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-44024 - Critical RCE in #Fluentd. Unvalidated ${tag} placeholder enables path traversal and arbitrary file write. #CVSS 9.8. No patch available. Mitigate immediately. #CVEAlert #infosec #devsecops #devops #sysadmin #developers #git #github #gitlab https://www.valtersit.com/cve/CVE-2026-44024

    Post summary

    The tweet announces CVE-2026-44024, a critical RCE in Fluentd with path traversal and arbitrary file write, notes no patch yet, and urges immediate mitigation.

    00020330
    1.0K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Patch

    Four Fluentd vulnerabilities are fixed in v1.19.3, including a 9.8 RCE (CVE-2026-44024) and SSRF (CVE-2026-44161). Patch now. #Fluentd #RCE #SSRF #CVE #Cybersecurity #Infosec https://securityonline.info/fluentd-vulnerabilities-v1-19-3 https://t.co/IZ9oEEP23H

    Post summary

    Fluentd v1.19.3 releases a patch for four vulnerabilities, including a 9.8 RCE (CVE-2026-44024) and an SSRF (CVE-2026-44161).

    00110541
    12.9K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Multiple vulnerabilities addressed in #Fluentd v1.19.3, including critical #RCE flaw #CVE-2026-44024 (CVSS 9.8). More info at: https://www.fluentd.org/blog/fluentd-v1.19.3-has-been-released/ #Patch #Patch #Patch

    Post summary

    The advisory announces that Fluentd v1.19.3 fixes a critical RCE CVE-2026-44024 (CVSS 9.8) and highlights the availability of a patch.

    01001378
    7.2K followersView on X
  • へっぽこ@tekitounaidda
    General

    Fluentdの脆弱性(CVE-2026-44024)に対応した時に、サーバで使っていたFluent Package v5がすでにサポート切れしてた事に気がついた😇 サーバ上のソフトウェア情報の収集はしてるけど、きちんと管理するのは大変だなぁ、、、お金かけずになんとか出来ればいいのだけど、、、

    Post summary

    The post notes that a Fluentd CVE was being addressed and that a related package is out of support, but provides no further technical, exploit, or patch details.

    0001099
    16 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-44024: Fluentd Arbitrary File Write Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04qCvmd0

    Post summary

    The post announces a newly disclosed CVE-2026-44024, an arbitrary file write vulnerability in Fluentd, and outlines its business implications and recommended responses.

    0000035
    32 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-44024 | Fluentd RCE via Path Traversal (CVSS 9.8) Insufficient validation of ${tag} placeholder allows attackers to write arbitrary files & achieve RCE. Affects versions <1.19.3. ✅ Update to v1.19.3 immediately #CVE #Vulnerability #PatchNow https://t.co/yssOMwjWl1

    Post summary

    The tweet highlights the critical CVE‑2026‑44024 RCE in Fluentd, details the path traversal flaw and CVSS score, and urges users to patch to v1.19.3 immediately.

    0000050
    71 followersView on X
  • ChrisUK2026@chris_uk2026
    Patch

    Four Fluentd vulnerabilities are fixed in v1.19.3, including a 9.8 RCE (CVE-2026-44024) and SSRF (CVE-2026-44161). Patch now. @the_yellow_fall #Fluentd #RCE #SSRF #CVE #Cybersecurity #Infosec http://securityonline.info/fluentd-vulner…

    Post summary

    The tweet announces the patch of four Fluentd vulnerabilities, including CVE-2026-44024 (RCE) and CVE-2026-44161 (SSRF), with no proof‑of‑concept or exploitation details shared.

    0000065
    25 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Fluentd `${tag}` path traversal enables arbitrary file write (CVE-2026-44024) Fluentd improperly validates the `${tag}` placeholder when building output file paths in file-based output configurations, allowing untrusted tags to influence filesystem writes. The root cause is path traversal due to improper input validation/sanitization of attacker-controlled path segments (e.g., `../`). An attacker can exploit this by sending crafted log events with malicious tags to a Fluentd instance that accepts logs from untrusted sources and uses `${tag}` in its output path, with success depending on runtime config and Fluentd’s process permissions. Impact ranges from arbitrary file write/overwrite outside intended directories to potential remote code execution by overwriting Fluentd config, plugins, or other executable components. 👉 Affected: fluentd (configs using `${tag}` in file path outputs; versions TBD) | Upgrade to Vendor fix version (not yet specified) or remove `${tag}` from paths and restrict input sources immediately

    Post summary

    CVE-2026-44024 exposes a path‑traversal flaw in Fluentd’s `${tag}` handling, enabling arbitrary file writes and potential remote code execution; a vendor fix and immediate mitigation steps are advised.

    0000093
    231 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Fluentd, Arbitrary File Write leading to Remote Code Execution (RCE), #CVE-2026-44024 (Critical) -DC-Jun2026-671 https://dailycve.com/fluentd-arbitrary-file-write-leading-to-remote-code-execution-rce-cve-2026-44024-critical-dc-jun2026-671/

    Post summary

    Fluentd has a newly disclosed critical vulnerability that allows arbitrary file writes and remote code execution; no patch, tool, or active exploitation evidence is reported.

    0000076
    216 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfluentdfluentd---

Explore more