CVE-2026-54370
HighAdvisory
Published 29 Jun 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.2
- base score, highest
- EPSS
- 0.001
- 0th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,450
- of 17,797 indexed, latest versions
- Container images
- 2,422
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
CVE-2026-54370 affecting package acl for versions less than 2.4.0-1
Carried by container images the latest versions of 2,450 of 17,797 indexed charts deploy, on 2,422 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| acldeb | 2.2.52-1, 2.2.52-3, 2.2.52-3build1, 2.2.53-6+8 more | 2.4.0-1 | 2,419 |
| aclrpm | 2.3.1-2.azl3 | 2.4.0-1 | 3 |
Charts affected
2,450 by stars
| Chart | Latest | Affected images | Radar Score |
|---|
Container images carrying it
2,422 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| clickhouse/ | e019438e1e05 | acl | no fix listed | 1 |
| clickhouse/ | fa394da808cc | acl | no fix listed | 1 |
| cloudtooling/ | f4f04e0fc401 | acl | no fix listed | 1 |
| cloudve/ | af56e77ca587 | acl | no fix listed | 1 |
| cloudve/ | d79c1c5881c0 | acl | no fix listed | 1 |
| clowder/ | 11f3d844e4c0 | acl | no fix listed | 1 |
| clowder/ | 14155326c7b9 | acl | no fix listed | 1 |
| clowder/ | bf146f1ca24f | acl | no fix listed | 1 |
| cm2network/ | 8cba47f53df5 | acl | no fix listed | 1 |
| codedesignplus/ | e336012bc781 | acl | no fix listed | 1 |
| codedesignplus/ | ac84661c605e | acl | no fix listed | 1 |
| codedesignplus/ | 360144457f4d | acl | no fix listed | 1 |
| codedesignplus/ | 3f6aaa32d526 | acl | no fix listed | 1 |
| collabora/ | 01dc4ab83977 | acl | no fix listed | 1 |
| collabora/ | 05299b452f7f | acl | no fix listed | 1 |
| conductoross/ | 9fba127693e6 | acl | no fix listed | 1 |
| consensys/ | 3a4f5761ae1c | acl | no fix listed | 1 |
| consensys/ | bf6ecd2ea716 | acl | no fix listed | 1 |
| consensys/ | f146a51a1ba3 | acl | no fix listed | 1 |
| contentsquareplatform/ | 24555f22d4be | acl | no fix listed | 1 |
| continuoussecuritytooling/ | f04ecefab64e | acl | no fix listed | 1 |
| cortezaproject/ | 0bcdcbcd3c63 | acl | no fix listed | 1 |
| cortezaproject/ | 8eb7a26605c9 | acl | no fix listed | 1 |
| cortezaproject/ | cb9f200de5d2 | acl | no fix listed | 1 |
| cortezaproject/ | 4ea78dfe5364 | acl | no fix listed | 1 |
| coturn/ | f4c2af06c3c5 | acl | no fix listed | 1 |
| countly/ | e3c238248f99 | acl | no fix listed | 1 |
| cradlepoint/ | 8f5720b0cd03 | acl | no fix listed | 1 |
| cribl/ | 762747cb6796 | acl | no fix listed | 1 |
| csiplugin/ | 1fa83d45417f | acl | no fix listed | 1 |
| cspconsole/ | 5524a26a6c23 | acl | no fix listed | 1 |
| cspconsole/ | 46dda4a31bd6 | acl | no fix listed | 1 |
| cspconsole/ | 39750248193b | acl | no fix listed | 1 |
| cspconsole/ | 9a2d8840bfdf | acl | no fix listed | 1 |
| cubejs/ | 34ac523a9bab | acl | no fix listed | 1 |
| curtismager20/ | 2c8bdd49aaee | acl | no fix listed | 1 |
| cybrarist/ | e9e2447ac666 | acl | no fix listed | 1 |
| cyfershepard/ | c4e2dfa8bddf | acl | no fix listed | 1 |
| cyverse/ | aa69d105b292 | acl | no fix listed | 1 |
| cznic/ | fe71c5214fdc | acl | no fix listed | 1 |
| dachichang/ | 7ccac90a935e | acl | no fix listed | 1 |
| daedalusproject/ | 6f72b5119eda | acl | no fix listed | 1 |
| dagster/ | 0505973033e1 | acl | no fix listed | 1 |
| dagster/ | 22036fc83927 | acl | no fix listed | 1 |
| danialnabiyan1382/ | f96a7ebf1f42 | acl | no fix listed | 1 |
| dannielkil/ | 937993927694 | acl | no fix listed | 1 |
| darthsim/ | 3b709e4a0e5e | acl | no fix listed | 1 |
| darthsim/ | 476cb08c816a | acl | no fix listed | 1 |
| darthsim/ | 7d12c7c8fc66 | acl | no fix listed | 1 |
| darthsim/ | f247c72df1d7 | acl | no fix listed | 1 |