StackRadar

CVE-2026-54411

High

Advisory

Published 14 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,470
of 17,828 indexed, latest versions
Container images
2,505
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: pam security update

Carried by container images the latest versions of 2,470 of 17,828 indexed charts deploy, on 2,505 images.

Affected packageAffected versionsFixed inImages
pamdeb1.1.8-1ubuntu2, 1.1.8-1ubuntu2.2, 1.1.8-3.2ubuntu2, 1.1.8-3.2ubuntu2.1+33 more1.4.0-11ubuntu2.7, 1.5.3-5ubuntu5.6, 1.7.0-5+e5, 1.7.0-5ubuntu3.12,325
pamrpm1.1.8-22.el7, 1.1.8-23.el7, 1.3.0-150000.6.86.1, 1.3.0-lp151.7.38+29 more0:1.1.8-23.el7_9.3, 0:1.3.1-40.el8_10, 0:1.5.1-27.el9_8.1, 0:1.5.1-28.el9_8.1+4 more180
OSV records
DEBIAN-CVE-2026-54411RHSA-2026:56131RHSA-2026:59379RHSA-2026:60224RHSA-2026:61227RHSA-2026:64815RLSA-2026:56131RLSA-2026:59379RLSA-2026:64815UBUNTU-CVE-2026-54411ECHO-a8ba-b20f-6ddaopenSUSE-SU-2026:11201-1SUSE-SU-2026:22639-1SUSE-SU-2026:3163-1
Also known as
RHSA-2026:61223, RHSA-2026:61224, RHSA-2026:61225, RHSA-2026:61226, RHSA-2026:61228, RHSA-2026:61230, USN-8601-1

Charts affected

2,470 by stars
ChartLatestAffected imagesRadar Score
flaresolverrm0nsterrr-flaresolverrVerified publisher2.4.11 of 1See more

flaresolverr m0nsterrr-flaresolverr 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.5.2c80ae007ce2c
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

6,800
drillmagasin-drill0.9.01 of 3See more

drill magasin-drill 0.9.0

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
merlos/zookeeper:3.9.3a38fc7e09ed7
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

5,810
redismagefleet-redis0.1.01 of 1See more

redis magefleet-redis 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/redis:7.20637954999d0
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

1,046
magentomagento3.2.36 of 12See more

magento magento 3.2.3

6 of the 12 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/mariadb:10.422edfe1c7834
pam@1.3.1-5ubuntu4.7
no fix listed
library/rabbitmq:4.1.0-management935b3f84c1e4
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6
library/redis:7.20637954999d0
pam@1.5.2-6+deb12u2
no fix listed
longhornio/longhorn-manager:v1.10.05b0bc1b88f0c
pam@1.3.0-150000.6.86.1
1.3.0-150000.6.89.1
longhornio/longhorn-share-manager:v1.10.09f6e5e3be8ab
pam@1.3.0-150000.6.86.1
1.3.0-150000.6.89.1
longhornio/longhorn-ui:v1.10.0e60f36161511
pam@1.3.0-150000.6.86.1
1.3.0-150000.6.89.1

Open the chart page →

13,824
maptiler-servermaptilerOfficialVerified publisher1.3.01 of 1See more

maptiler-server maptiler 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
maptiler/server:4.8.07e206140057b
pam@1.3.1-5ubuntu4.7
no fix listed

Open the chart page →

3,070
Practica_4_Recuperacion_helmmca-03-02-practica4-recuperacionVerified publisher1.0.11 of 6See more

Practica_4_Recuperacion_helm mca-03-02-practica4-recuperacion 1.0.1

1 of the 6 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/mongo:4.2.358b25d51baa1
pam@1.1.8-3.6ubuntu2.18.04.1
no fix listed

Open the chart page →

19,240
mcpmcp-chartsVerified publisher0.0.232 of 7See more

mcp mcp-charts 0.0.23

2 of the 7 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/gla-rad/mc-mms-edgerouter:latest3620d5680775
pam@1.7.0-5
no fix listed
ghcr.io/gla-rad/mc-mms-router:latest032e977d9adf
pam@1.7.0-5
no fix listed

Open the chart page →

7,209
jellyfinmedia-servarrVerified publisher0.17.11 of 2See more

jellyfin media-servarr 0.17.1

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
pam@1.7.0-5
no fix listed

Open the chart page →

2,681
mw-kube-agent-v2middleware-labsVerified publisher2.8.61 of 1See more

mw-kube-agent-v2 middleware-labs 2.8.6

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6

Open the chart page →

4,290
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
pam@1.7.0-5ubuntu2
no fix listed

Open the chart page →

35,215
model-manager-loadermodel-manager-loader1.27.01 of 1See more

model-manager-loader model-manager-loader 1.27.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
pam@1.7.0-5
no fix listed

Open the chart page →

2,742
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

13,827
redminemt1905027.3.42 of 3See more

redmine mt190502 7.3.4

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/postgres:1886c951e05bf5
pam@1.7.0-5
no fix listed
library/redmine:6.1.204ac44a2595b
pam@1.7.0-5
no fix listed

Open the chart page →

7,204
12factormyaVerified publisher24.1.21 of 1See more

12factor mya 24.1.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
pam@1.7.0-5
no fix listed

Open the chart page →

1,589
my-react-appmy-react-app0.1.51 of 1See more

my-react-app my-react-app 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
pam@1.7.0-5
no fix listed

Open the chart page →

1,589
n3uronn3uronVerified publisher0.3.51 of 1See more

n3uron n3uron 0.3.5

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
n3uronhub/n3uron:v1.22.4423a0bdd9cb9
pam@1.7.0-5
no fix listed

Open the chart page →

1,929
satisfactorynaj981.1.11 of 1See more

satisfactory naj98 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.1199be1064b18
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7

Open the chart page →

3,775
spring-helmnaveenalla-springboot1.0.01 of 2See more

spring-helm naveenalla-springboot 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
pam@1.7.0-5
no fix listed

Open the chart page →

1,268
clowder2ncsaVerified publisher1.9.75 of 12See more

clowder2 ncsa 1.9.7

5 of the 12 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.215d4647fd491
pam@1.5.2-6+deb12u1
no fix listed
bitnamilegacy/os-shell:12-debian-12-r16d24925821dd2
pam@1.5.2-6+deb12u1
no fix listed
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
pam@1.5.2-6+deb12u1
no fix listed
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
pam@1.5.2-6+deb12u1
no fix listed
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

37,915
nginx-chartnginx-chart-testVerified publisher0.1.11 of 1See more

nginx-chart nginx-chart-test 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
pam@1.7.0-5
no fix listed

Open the chart page →

1,589
cloud9nicholaswildeVerified publisher1.0.01 of 1See more

cloud9 nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
linuxserver/cloud9:version-1.29.245c5fe102ff3
pam@1.1.8-3.6ubuntu2.18.04.3
no fix listed

Open the chart page →

11,757
papermergenicholaswildeVerified publisher1.0.21 of 1See more

papermerge nicholaswilde 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/papermerge:version-v2.0.198ba2dd3f0bd
pam@1.3.1-5ubuntu4.3
no fix listed

Open the chart page →

20,368
writefreelynicholaswildeVerified publisher1.0.01 of 1See more

writefreely nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/writefreely:version-0.13.1c3c8481b7e56
pam@1.1.8-3.6ubuntu2.18.04.3
no fix listed

Open the chart page →

8,130
helm-composenousefreakVerified publisher0.1.32 of 2See more

helm-compose nousefreak 0.1.3

2 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/mariadb:10.8.2-focal490f01279be1
pam@1.3.1-5ubuntu4.3
no fix listed
library/wordpress:latesta85a30d9e752
pam@1.7.0-5
no fix listed

Open the chart page →

13,684
nginx-s3olopostVerified publisher0.2.11 of 1See more

nginx-s3 olopost 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss3db8145349a3
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

5,115
onechartonechart-slVerified publisher0.76.01 of 1See more

onechart onechart-sl 0.76.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
pam@1.7.0-5
no fix listed

Open the chart page →

1,589
opencatalogiopencatalogi1.0.62 of 8See more

opencatalogi opencatalogi 1.0.6

2 of the 8 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
pam@1.5.2-6
no fix listed
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

14,990
dhcp-serveropencord1.0.21 of 1See more

dhcp-server opencord 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
networkboot/dhcpd:lateste99bbfbd6fb2
pam@1.4.0-11ubuntu2
1.4.0-11ubuntu2.7

Open the chart page →

4,398
opencveopencve1.2.01 of 3See more

opencve opencve 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
cleveritcz/opencve:1.5.0c75c1636e0b7
pam@1.5.1-15.el9
0:1.5.1-28.el9_8.1

Open the chart page →

2,133
librechatopenshift1.9.02 of 3See more

librechat openshift 1.9.0

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/mongo:8.0.20098862b1339f
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

5,943
opentelemetry-demoopentelemetry-helmOfficialVerified publisher0.42.07 of 34See more

opentelemetry-demo opentelemetry-helm 0.42.0

7 of the 34 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
pam@1.7.0-5
no fix listed
ghcr.io/open-telemetry/demo:3.1.0-chatbot604b1f493c92
pam@1.7.0-5
no fix listed
ghcr.io/open-telemetry/demo:3.1.0-mcp81db69cdd0b6
pam@1.7.0-5
no fix listed
ghcr.io/open-telemetry/demo:3.1.0-flagd-ui97a3d37e709f
pam@1.7.0-5
no fix listed
ghcr.io/open-telemetry/demo:3.1.0-load-generatorb130d6cee6cb
pam@1.5.2-6+deb12u2
no fix listed
ghcr.io/open-telemetry/demo:3.1.0-agentd0f4ae0b32a8
pam@1.7.0-5
no fix listed
ghcr.io/open-telemetry/demo:3.1.0-addfd7a4697116
pam@1.5.3-5ubuntu5.4
1.5.3-5ubuntu5.6

Open the chart page →

20,236
openvaultopenvaultVerified publisher0.8.11 of 2See more

openvault openvault 0.8.1

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

7,011
rustfs-operatoroperatorVerified publisher0.7.01 of 1See more

rustfs-operator operator 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
rustfs/operator:0.07b96f986e5991
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

1,015
opikopikOfficialVerified publisher2.2.722 of 13See more

opik opik 2.2.72

2 of the 13 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/zookeeper:3.9.4dfa9ba46d14b
pam@1.4.0-11ubuntu2.6
1.4.0-11ubuntu2.7
redis/redis-stack-server:7.2.0-v10e44b2b49d059
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7

Open the chart page →

14,981
opsopsVerified publisher1.2.01 of 2See more

ops ops 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
shaowenchen/ops-server:latest6bac5cebd125
pam@1.4.0-11ubuntu2.6
1.4.0-11ubuntu2.7

Open the chart page →

91,111
palworldpalworld-server-chartVerified publisher2.7.11 of 1See more

palworld palworld-server-chart 2.7.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
thijsvanloef/palworld-server-docker:v2.7.1401d3eb5c053
pam@1.7.0-5
no fix listed

Open the chart page →

3,780
paperless-ngxpaperlessVerified publisher0.4.03 of 3See more

paperless-ngx paperless 0.4.0

3 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
bitnamilegacy/postgresqldigest-pinned926356130b77
pam@1.5.2-6+deb12u1
no fix listed
valkey/valkey:9.0.54c64dfeae602
pam@1.7.0-5
no fix listed
ghcr.io/paperless-ngx/paperless-ngxdigest-pinnedaa810a36942c
pam@1.7.0-5
no fix listed

Open the chart page →

8,685
uptime-kumapascaliskeVerified publisher3.0.01 of 1See more

uptime-kuma pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

6,976
fahclientpcktdmp2.6.01 of 2See more

fahclient pcktdmp 2.6.0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
foldingathome/fah-gpu:latest5ef7742d1eb4
pam@1.1.8-3.6ubuntu2.18.04.3
no fix listed

Open the chart page →

4,629
peertubepeertubeVerified publisher0.1.31 of 1See more

peertube peertube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
chocobozzz/peertube:v8.1.5052712130691
pam@1.7.0-5
no fix listed

Open the chart page →

7,122
spring-boot-api-apppiominVerified publisher0.3.111 of 1See more

spring-boot-api-app piomin 0.3.11

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
pam@1.4.0-11ubuntu2
1.4.0-11ubuntu2.7

Open the chart page →

7,667
playgroundplayground0.1.11 of 1See more

playground playground 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
pam@1.7.0-5
no fix listed

Open the chart page →

1,589
matomopockostVerified publisher1.3.02 of 3See more

matomo pockost 1.3.0

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
pam@1.7.0-5
no fix listed
pockost/matomo:5.13.07f5d293cbe4e
pam@1.7.0-5
no fix listed

Open the chart page →

5,355
portraitportraitVerified publisher0.2.132 of 8See more

portrait portrait 0.2.13

2 of the 8 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.0332c6d416808
pam@1.3.1-5ubuntu4.3
no fix listed
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

32,167
postgresqlpostgresql-helm0.1.21 of 1See more

postgresql postgresql-helm 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/postgres:16a3b7f434b2dc
pam@1.7.0-5
no fix listed

Open the chart page →

1,268
JenkinsprasoonjenkinsVerified publisher0.1.01 of 1See more

Jenkins prasoonjenkins 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
pam@1.7.0-5
no fix listed

Open the chart page →

2,545
privacyideaprivacyidea1.0.61 of 2See more

privacyidea privacyidea 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/mariadb:11.7.2fcc7fcd7114a
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6

Open the chart page →

5,597
prowlerprowler-appVerified publisher0.0.92 of 5See more

prowler prowler-app 0.0.9

2 of the 5 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/neo4j:2026.02.25ab4ab0358cf
pam@1.7.0-5
no fix listed
prowlercloud/prowler-api:5.31.14f252d579be2
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

8,493
pzserverpzserver0.1.171 of 2See more

pzserver pzserver 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
lis314/project-zomboid-docker:latestaa2089c37920
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

3,270
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6

Open the chart page →

56,167

Container images carrying it

2,505 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
pam@1.5.2-6+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
pam@1.5.2-6+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
pam@1.5.2-6+deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
pam@1.5.2-6+deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
pam@1.5.2-6+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.