CVE-2026-54411
HighAdvisory
Published 14 Jun 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.2
- base score, highest
- EPSS
- 0.003
- 25th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,401
- of 17,790 indexed, latest versions
- Container images
- 2,413
- deployed by those charts
- Fix available
- 3 of 3
- affected packages
Red Hat Security Advisory: pam security update
Carried by container images the latest versions of 2,401 of 17,790 indexed charts deploy, on 2,413 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| pamdeb | 1.1.8-1ubuntu2, 1.1.8-1ubuntu2.2, 1.1.8-3.2ubuntu2, 1.1.8-3.2ubuntu2.1+33 more | 1.4.0-11ubuntu2.7, 1.5.3-5ubuntu5.6, 1.7.0-5+e5, 1.7.0-5ubuntu3.1 | 2,232 |
| linux-pamapk | 1.7.2-r4 | 1.7.2-r5 | 4 |
| pamrpm | 1.1.8-22.el7, 1.1.8-23.el7, 1.3.0-150000.6.86.1, 1.3.0-lp151.7.38+28 more | 0:1.1.8-23.el7_9.3, 0:1.3.1-40.el8_10, 0:1.5.1-27.el9_8.1, 0:1.5.1-28.el9_8.1+4 more | 177 |
- OSV records
- CGA-6xpv-g74w-9xwfDEBIAN-CVE-2026-54411RHSA-2026:56131RHSA-2026:59379RHSA-2026:60224RHSA-2026:61227RHSA-2026:64815RLSA-2026:56131RLSA-2026:59379RLSA-2026:64815UBUNTU-CVE-2026-54411ECHO-a8ba-b20f-6ddaopenSUSE-SU-2026:11201-1SUSE-SU-2026:22639-1SUSE-SU-2026:3163-1
- Also known as
- CGA-jvfq-ppr4-246f, RHSA-2026:61223, RHSA-2026:61224, RHSA-2026:61225, RHSA-2026:61226, RHSA-2026:61228, RHSA-2026:61230, USN-8601-1
Charts affected
2,401 by stars
Container images carrying it
2,413 by charts deploying them
A fixed version is listed for 3 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| confluentinc/ | b0b7aa26254a | pam | 0:1.3.1-40.el8_10 | 1 |
| confluentinc/ | 8ec46c27982f | pam | 0:1.3.1-40.el8_10 | 1 |
| confluentinc/ | ee403d5b9090 | pam | 0:1.3.1-40.el8_10 | 1 |
| confluentinc/ | b651d4b6185a | pam | 0:1.3.1-40.el8_10 | 1 |
| confluentinc/ | 0bec03c1f3ce | pam | 0:1.3.1-40.el8_10 | 1 |
| confluentinc/ | 5ca5f3269814 | pam | 0:1.3.1-40.el8_10 | 1 |
| confluentinc/ | 78c190f4472c | pam | 0:1.3.1-40.el8_10 | 1 |
| consensys/ | bf6ecd2ea716 | pam | 1.5.3-5ubuntu5.6 | 1 |
| contentsquareplatform/ | 24555f22d4be | pam | no fix listed | 1 |
| continuoussecuritytooling/ | f04ecefab64e | pam | no fix listed | 1 |
| cortezaproject/ | 0bcdcbcd3c63 | pam | 1.4.0-11ubuntu2.7 | 1 |
| cortezaproject/ | 8eb7a26605c9 | pam | no fix listed | 1 |
| cortezaproject/ | cb9f200de5d2 | pam | 1.4.0-11ubuntu2.7 | 1 |
| cortezaproject/ | 4ea78dfe5364 | pam | no fix listed | 1 |
| coturn/ | f4c2af06c3c5 | pam | no fix listed | 1 |
| countly/ | e3c238248f99 | pam | no fix listed | 1 |
| cradlepoint/ | 8f5720b0cd03 | pam | no fix listed | 1 |
| cribl/ | 762747cb6796 | pam | no fix listed | 1 |
| csiplugin/ | 1fa83d45417f | pam | no fix listed | 1 |
| cspconsole/ | 5524a26a6c23 | pam | no fix listed | 1 |
| cspconsole/ | 46dda4a31bd6 | pam | no fix listed | 1 |
| cspconsole/ | 39750248193b | pam | no fix listed | 1 |
| cspconsole/ | 9a2d8840bfdf | pam | no fix listed | 1 |
| cubejs/ | 34ac523a9bab | pam | no fix listed | 1 |
| cybrarist/ | e9e2447ac666 | pam | no fix listed | 1 |
| cyfershepard/ | c4e2dfa8bddf | pam | no fix listed | 1 |
| cznic/ | fe71c5214fdc | pam | no fix listed | 1 |
| dachichang/ | 7ccac90a935e | pam | no fix listed | 1 |
| daedalusproject/ | 6f72b5119eda | pam | no fix listed | 1 |
| dagster/ | e29a64392e12 | pam | no fix listed | 1 |
| dagster/ | 9674f3b94a3b | pam | no fix listed | 1 |
| danialnabiyan1382/ | f96a7ebf1f42 | pam | no fix listed | 1 |
| dannielkil/ | 937993927694 | pam | no fix listed | 1 |
| darthsim/ | 3b709e4a0e5e | pam | 1.5.3-5ubuntu5.6 | 1 |
| darthsim/ | 476cb08c816a | pam | 1.5.3-5ubuntu5.6 | 1 |
| darthsim/ | 7d12c7c8fc66 | pam | 1.5.3-5ubuntu5.6 | 1 |
| daskdev/ | 052630f5ca04 | pam | no fix listed | 1 |
| dasmeta/ | fa657960dfec | pam | no fix listed | 1 |
| datadog/ | aad9994de6a7 | pam | 1.5.3-5ubuntu5.6 | 1 |
| datafuselabs/ | ba877ee6cb4d | pam | no fix listed | 1 |
| datafuselabs/ | a936843b85b4 | pam | no fix listed | 1 |
| datalayers/ | 17b292079239 | pam | 1.4.0-11ubuntu2.7 | 1 |
| datalust/ | 9c731bb207a6 | pam | no fix listed | 1 |
| datalust/ | 3de34aed5642 | pam | no fix listed | 1 |
| datamate/ | 2dd66b722464 | pam | 1.4.0-11ubuntu2.7 | 1 |
| dbeaver/ | 87ab86d00f8c | pam | 1.5.3-5ubuntu5.6 | 1 |
| dbgate/ | f2dc7423ea88 | pam | no fix listed | 1 |
| dblaci/ | eea697611af4 | pam | 1.4.0-11ubuntu2.7 | 1 |
| ddosify/ | ea602056d9ce | pam | no fix listed | 1 |
| ddosify/ | a43c5155fa1c | pam | no fix listed | 1 |