← Vulnerability feed

Vulnerability record · CVE-2026-44025 · published 8 July 2026

CVE-2026-44025: Fluentd missing authentication for critical function vulnerability

Fluentd · Fluentd

Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's Monitor Agent plugin in_monitor_agent exposes internal metrics and plugin information via a REST API, and responses from /api/plugins.json and related endpoints unintentionally include internal instance variables that may contain database passwords, API keys, or cloud credentials. This issue is fixed in version 1.19.3.

7.5 CVSS 3.1 High EPSS 0.47% · top 61.5% CWE-306 · Missing authentication for critical function
7.5CVSS 3.1 base score
0.47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jul 2026Last modified by NVD

Description

Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's Monitor Agent plugin in_monitor_agent exposes internal metrics and plugin information via a REST API, and responses from /api/plugins.json and related endpoints unintentionally include internal instance variables that may contain database passwords, API keys, or cloud credentials. This issue is fixed in version 1.19.3.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-44025 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-44024Fluentd path traversal vulnerabilityFluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd allo…EPSS 1.1%9.8CVE-2022-39379Fluentd unauthenticated RCE via unsafe JSON deserializationFluentd, when the non-default environment variable FLUENT_OJ_OPTION_MODE is set to object, deserializes untrusted JSON payloads unsafely, allowing re…EPSS 45%analysed9.8CVE-2017-10906Fluentd vulnerabilityEscape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitr…EPSS 4.6%8.8CVE-2020-21514Fluentd incorrect default permissions vulnerabilityAn issue was discovered in Fluent-ui v.1.2.2 allows attackers to gain escalated privileges and execute arbitrary code due to a default password.EPSS 0.79%7.5CVE-2026-44160Fluentd vulnerabilityFluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's in…EPSS 0.62%7.5CVE-2021-41186Fluentd uncontrolled resource consumption vulnerabilityFluentd collects events from various data sources and writes them to files to help unify logging infrastructure. The parser_apache2 plugin in Fluentd…EPSS 2.2%7.2CVE-2026-44161Fluentd server-side request forgery (ssrf) vulnerabilityFluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, the Fluentd …EPSS 0.44%8.8CVE-2026-67277MikroTik RouterOS btest missing authentication leaks kernel memory and crashes kernelRouterOS accepts a "related" btest connection before the primary session is authenticated, letting an unauthenticated client start an IPv4 UDP test. …KEVEPSS 1.6%analysed

Source: NIST National Vulnerability Database (record CVE-2026-44025), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.