CVE-2026-54411
HighAdvisory
Published 14 Jun 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.2
- base score, highest
- EPSS
- 0.003
- 25th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,423
- of 17,828 indexed, latest versions
- Container images
- 2,448
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
Red Hat Security Advisory: pam security update
Carried by container images the latest versions of 2,423 of 17,828 indexed charts deploy, on 2,448 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| pamdeb | 1.1.8-1ubuntu2, 1.1.8-1ubuntu2.2, 1.1.8-3.2ubuntu2, 1.1.8-3.2ubuntu2.1+33 more | 1.4.0-11ubuntu2.7, 1.5.3-5ubuntu5.6, 1.7.0-5+e5, 1.7.0-5ubuntu3.1 | 2,272 |
| pamrpm | 1.1.8-22.el7, 1.1.8-23.el7, 1.3.0-150000.6.86.1, 1.3.0-lp151.7.38+29 more | 0:1.1.8-23.el7_9.3, 0:1.3.1-40.el8_10, 0:1.5.1-27.el9_8.1, 0:1.5.1-28.el9_8.1+4 more | 176 |
- OSV records
- DEBIAN-CVE-2026-54411RHSA-2026:56131RHSA-2026:59379RHSA-2026:60224RHSA-2026:61227RHSA-2026:64815RLSA-2026:56131RLSA-2026:59379RLSA-2026:64815UBUNTU-CVE-2026-54411ECHO-a8ba-b20f-6ddaopenSUSE-SU-2026:11201-1SUSE-SU-2026:22639-1SUSE-SU-2026:3163-1
- Also known as
- RHSA-2026:61223, RHSA-2026:61224, RHSA-2026:61225, RHSA-2026:61226, RHSA-2026:61228, RHSA-2026:61230, USN-8601-1
Charts affected
2,423 by stars
| Chart | Latest | Affected images | Radar Score |
|---|
Container images carrying it
2,448 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| sigp/ | 50f66cfebb6d | pam | 1.4.0-11ubuntu2.7 | 3 |
| vaultwarden/ | ebdfe70701c6 | pam | no fix listed | 3 |
| xenondb/ | 0e26872a2b67 | pam | no fix listed | 3 |
| ghcr.io/ | f65f53dd9668 | pam | no fix listed | 3 |
| ghcr.io/ | 19ebe07b4daf | pam | no fix listed | 3 |
| ghcr.io/ | 6a5594b7b32c | pam | no fix listed | 3 |
| ghcr.io/ | 096dae27b5d6 | pam | no fix listed | 3 |
| ghcr.io/ | cf9b41e17b93 | pam | no fix listed | 3 |
| ghcr.io/ | c80ae007ce2c | pam | no fix listed | 3 |
| ghcr.io/ | 0502794a4d86 | pam | no fix listed | 3 |
| ghcr.io/ | 673d5229df1f | pam | no fix listed | 3 |
| quay.io/ | 6545dac92173 | pam | no fix listed | 3 |
| quay.io/ | 2b6db27eaf3d | pam | 1.4.0-11ubuntu2.7 | 3 |
| quay.io/ | bc4aa22272ef | pam | 0:1.3.1-40.el8_10 | 3 |
| quay.io/ | 5bf041aacadd | pam | 1.5.3-5ubuntu5.6 | 3 |
| quay.io/ | 60566529446a | pam | 1.5.3-5ubuntu5.6 | 3 |
| quay.io/ | 721b5c9634d4 | pam | 1.5.3-5ubuntu5.6 | 3 |
| quay.io/ | 9795f3f9f031 | pam | 1.5.3-5ubuntu5.6 | 3 |
| quay.io/ | 39f2c6e0af38 | pam | no fix listed | 3 |
| quay.io/ | 01d5d8c4cecb | pam | 1.5.3-5ubuntu5.6 | 3 |
| quay.io/ | 4c3b91bebd3d | pam | no fix listed | 3 |
| quay.io/ | f296c2ec5db7 | pam | 1.4.0-11ubuntu2.7 | 3 |
| quay.io/ | 9d25865295af | pam | 1.5.3-5ubuntu5.6 | 3 |
| quay.io/ | ea6dd1e4ce71 | pam | 1.5.3-5ubuntu5.6 | 3 |
| quay.io/ | 709c7da19c5a | pam | no fix listed | 3 |
| quay.io/ | a7dff785d821 | pam | 0:1.3.1-40.el8_10 | 3 |
| actualbudget/ | 552beab3dec8 | pam | no fix listed | 2 |
| alazidis/ | 0e8c84152201 | pam | 1.5.3-5ubuntu5.6 | 2 |
| apache/ | 7cdfd8deec92 | pam | 1.4.0-11ubuntu2.7 | 2 |
| apache/ | 319cd8a81ed1 | pam | 1.5.3-5ubuntu5.6 | 2 |
| apacherocketmq/ | ce78506bd6fe | pam | 0:1.5.1-27.el9_8.1 | 2 |
| apache/ | 92d055a84e9e | pam | 1.4.0-11ubuntu2.7 | 2 |
| apache/ | ae0b86d3c4d0 | pam | 1.5.3-5ubuntu5.6 | 2 |
| bitnamilegacy/ | 00176a47afa0 | pam | no fix listed | 2 |
| bitnamilegacy/ | 33ce23601fc9 | pam | no fix listed | 2 |
| bitnamilegacy/ | 94bc968141e7 | pam | no fix listed | 2 |
| bitnamilegacy/ | 5927ff3702df | pam | no fix listed | 2 |
| bitnami/ | ab4d5b45116e | pam | no fix listed | 2 |
| blockstack/ | f79944317326 | pam | no fix listed | 2 |
| cagriekin/ | 99e17aa165df | pam | no fix listed | 2 |
| cfssl/ | c9018c2ddf0b | pam | no fix listed | 2 |
| chromedp/ | 313ed7255ae1 | pam | no fix listed | 2 |
| clickhouse/ | ed9640bfff07 | pam | no fix listed | 2 |
| confluentinc/ | ac776fad95a5 | pam | 0:1.3.1-40.el8_10 | 2 |
| confluentinc/ | 7610a50b13e7 | pam | 0:1.3.1-40.el8_10 | 2 |
| confluentinc/ | cae577096489 | pam | 0:1.3.1-40.el8_10 | 2 |
| deepflowce/ | bc1882f75c18 | pam | no fix listed | 2 |
| eqalpha/ | 6537505c4235 | pam | no fix listed | 2 |
| eqalpha/ | eceb1806730c | pam | no fix listed | 2 |
| fireflyiii/ | fe4ecec4c2ba | pam | no fix listed | 2 |