StackRadar

CVE-2026-54411

High

Advisory

Published 14 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,470
of 17,828 indexed, latest versions
Container images
2,505
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: pam security update

Carried by container images the latest versions of 2,470 of 17,828 indexed charts deploy, on 2,505 images.

Affected packageAffected versionsFixed inImages
pamdeb1.1.8-1ubuntu2, 1.1.8-1ubuntu2.2, 1.1.8-3.2ubuntu2, 1.1.8-3.2ubuntu2.1+33 more1.4.0-11ubuntu2.7, 1.5.3-5ubuntu5.6, 1.7.0-5+e5, 1.7.0-5ubuntu3.12,325
pamrpm1.1.8-22.el7, 1.1.8-23.el7, 1.3.0-150000.6.86.1, 1.3.0-lp151.7.38+29 more0:1.1.8-23.el7_9.3, 0:1.3.1-40.el8_10, 0:1.5.1-27.el9_8.1, 0:1.5.1-28.el9_8.1+4 more180
OSV records
DEBIAN-CVE-2026-54411RHSA-2026:56131RHSA-2026:59379RHSA-2026:60224RHSA-2026:61227RHSA-2026:64815RLSA-2026:56131RLSA-2026:59379RLSA-2026:64815UBUNTU-CVE-2026-54411ECHO-a8ba-b20f-6ddaopenSUSE-SU-2026:11201-1SUSE-SU-2026:22639-1SUSE-SU-2026:3163-1
Also known as
RHSA-2026:61223, RHSA-2026:61224, RHSA-2026:61225, RHSA-2026:61226, RHSA-2026:61228, RHSA-2026:61230, USN-8601-1

Charts affected

2,470 by stars
ChartLatestAffected imagesRadar Score
backendzymtraceOfficialVerified publisher26.9.23 of 6See more

backend zymtrace 26.9.2

3 of the 6 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.3.14.14b627d7a9bc0e
pam@1.4.0-11ubuntu2.6
1.4.0-11ubuntu2.7
library/postgres:17.4304ab8135187
pam@1.5.2-6+deb12u1
no fix listed
ghcr.io/zystem-io/zymtrace-pub-gateway:26.9.2ae9ae0925ff8
pam@1.4.0-11ubuntu2.6
1.4.0-11ubuntu2.7

Open the chart page →

9,363
acos-prometheus-exporter-helm-charta10-prometheus-exporter0.1.01 of 1See more

acos-prometheus-exporter-helm-chart a10-prometheus-exporter 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
a10networks/acos-prometheus-exporter:latest8dc58d434d71
pam@1.1.8-3.6ubuntu2.18.04.1
no fix listed

Open the chart page →

76,024
abstract-nodeabstract-nodeVerified publisher0.1.491 of 2See more

abstract-node abstract-node 0.1.49

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
matterlabs/external-node:9734bf2-17870579939295dadc06bdf3b
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

4,597
active-mqactivemq-helm-chartVerified publisher1.8.21 of 3See more

active-mq activemq-helm-chart 1.8.2

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.44.00305c26f19ed
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6

Open the chart page →

3,341
open5gsadaptivenetlabVerified publisher1.0.32 of 3See more

open5gs adaptivenetlab 1.0.3

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
free5gmano/nextepc-mongodb:latest36f806935519
pam@1.1.8-3.2ubuntu2.1
no fix listed
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
pam@1.3.1-5ubuntu4.1
no fix listed

Open the chart page →

101,683
jenkinsaditisingh-jenkins1.0.01 of 1See more

jenkins aditisingh-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
pam@1.7.0-5
no fix listed

Open the chart page →

2,545
gotenbergadnoctemVerified publisher0.5.01 of 1See more

gotenberg adnoctem 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.37.0f29984bd1e22
pam@1.7.0-5
no fix listed

Open the chart page →

6,288
lhciadnoctemVerified publisher0.1.01 of 1See more

lhci adnoctem 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/adnoctem/lhci:1.0.119553e4b4033
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

1,303
linkwardenadnoctemVerified publisher0.5.11 of 2See more

linkwarden adnoctem 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

3,907
outlineadnoctemVerified publisher0.1.21 of 1See more

outline adnoctem 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
outlinewiki/outline:1.10.1832051f039b4
pam@1.7.0-5
no fix listed

Open the chart page →

1,282
uptime-kumaadnoctemVerified publisher0.4.11 of 1See more

uptime-kuma adnoctem 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

30,720
bootaerokube1.0.12 of 4See more

boot aerokube 1.0.1

2 of the 4 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
quay.io/aerokube/jumphost:1.0.170fd7c00418d
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7
quay.io/aerokube/keygen:1.0.1578934444f04
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7

Open the chart page →

8,009
aerospike-kubernetes-operatoraerospike4.5.01 of 1See more

aerospike-kubernetes-operator aerospike 4.5.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
aerospike/aerospike-kubernetes-operator:4.5.070a9eeb991b8
pam@1.6.1-9.el10
0:1.6.1-9.el10_2.1

Open the chart page →

638
msockperfaetrius2.0.82 of 2See more

msockperf aetrius 2.0.8

2 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/aetrius/msockperf-client/msockperf-client:main820af919c5e2
pam@1.5.3-5ubuntu5
1.5.3-5ubuntu5.6
ghcr.io/aetrius/msockperf-server/msockperf-server:main46ae4ea003e0
pam@1.5.3-5ubuntu5
1.5.3-5ubuntu5.6

Open the chart page →

4,343
kourierahhhhVerified publisher0.18.11 of 1See more

kourier ahhhh 0.18.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.34-latestcfc0678bc03c
pam@1.4.0-11ubuntu2.6
1.4.0-11ubuntu2.7

Open the chart page →

1,854
ahnlich-dbahnlich-dbVerified publisher0.1.11 of 1See more

ahnlich-db ahnlich-db 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/deven96/ahnlich-db:latest45d8b5aab491
pam@1.7.0-5
no fix listed

Open the chart page →

1,632
airbyte-keycloakairbyteVerified publisher0.1.21 of 2See more

airbyte-keycloak airbyte 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/postgres:17f4c66b820c6f
pam@1.7.0-5
no fix listed

Open the chart page →

1,268
pod-sweeperairbyteVerified publisher1.5.11 of 1See more

pod-sweeper airbyte 1.5.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
airbyte/pod-sweeper:1.5.198d2c39d512e
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

5,016
airbyteairbyte-v2Verified publisher2.3.01 of 10See more

airbyte airbyte-v2 2.3.0

1 of the 10 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
airbyte/manifest-server:7.28.2deec511b51c3
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

12,181
aktoakto0.2.02 of 7See more

akto akto 0.2.0

2 of the 7 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
pam@1.3.1-25.el8
0:1.3.1-40.el8_10
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
pam@1.3.1-25.el8
0:1.3.1-40.el8_10

Open the chart page →

13,886
akto-ai-guardrails-v2akto0.3.05 of 6See more

akto-ai-guardrails-v2 akto 0.3.0

5 of the 6 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
aktosecurity/akto-agent-guard-anonymizer:1.1.4d4b100cbdc47
pam@1.7.0-5
no fix listed
aktosecurity/akto-agent-guard-embedder:1.1.4dbc566b2376c
pam@1.7.0-5
no fix listed
aktosecurity/akto-agent-guard-worker:1.1.4666eaffd5362
pam@1.7.0-5
no fix listed
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
pam@1.7.0-5ubuntu3
1.7.0-5ubuntu3.1
redis/redis-stack-server:7.4.0-v172035434f455
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7

Open the chart page →

42,635
akto-mini-runtimeakto0.7.221 of 3See more

akto-mini-runtime akto 0.7.22

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/redis:latestV8.6.2832d7785830f
pam@1.7.0-5
no fix listed

Open the chart page →

2,687
akto-mini-runtime-shaakto0.7.231 of 3See more

akto-mini-runtime-sha akto 0.7.23

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/redisdigest-pinned47200b041382
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

3,299
akto-mini-testingakto1.45.71 of 5See more

akto-mini-testing akto 1.45.7

1 of the 5 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-ai-automated-testing:latest573542399fe4
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

6,606
akto-mini-testing-kafkaakto1.42.12 of 5See more

akto-mini-testing-kafka akto 1.42.1

2 of the 5 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
pam@1.3.1-36.el8_10
0:1.3.1-40.el8_10
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
pam@1.3.1-36.el8_10
0:1.3.1-40.el8_10

Open the chart page →

6,450
akto-protectionakto0.1.02 of 4See more

akto-protection akto 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
pam@1.3.1-25.el8
0:1.3.1-40.el8_10
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
pam@1.3.1-25.el8
0:1.3.1-40.el8_10

Open the chart page →

11,337
akto-regional-setupakto1.4.02 of 9See more

akto-regional-setup akto 1.4.0

2 of the 9 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
pam@1.7.0-5ubuntu3
1.7.0-5ubuntu3.1
redis/redis-stack-server:7.4.072035434f455
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7

Open the chart page →

40,759
akto-testing-db-layerakto1.42.171 of 2See more

akto-testing-db-layer akto 1.42.17

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6

Open the chart page →

35,334
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6

Open the chart page →

57,534
cliproxyapialekcVerified publisher0.5.81 of 1See more

cliproxyapi alekc 0.5.8

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
eceasy/cli-proxy-api:v7.3.10ee21d2cc4b8f
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

1,093
esphomealekcVerified publisher2.9.01 of 1See more

esphome alekc 2.9.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
esphome/esphome:2026.9.09959730a04c7
pam@1.7.0-5
no fix listed

Open the chart page →

3,242
komodoalekcVerified publisher3.1.01 of 1See more

komodo alekc 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/moghtech/komodo-core:2.3.3bca73d0eee14
pam@1.7.0-5
no fix listed

Open the chart page →

1,957
alertigatealertigate0.6.01 of 1See more

alertigate alertigate 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/feresberbeche/alertigate:2.0.07b9bba80f207
pam@1.7.0-5
no fix listed

Open the chart page →

1,361
esphomealexmorbo-esphomeVerified publisher1.0.01 of 1See more

esphome alexmorbo-esphome 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
esphome/esphome:2024.12.2b2c6322700ac
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

6,391
flaresolverralexmorbo-flaresolverrVerified publisher0.2.01 of 1See more

flaresolverr alexmorbo-flaresolverr 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

27,797
slskdalexmorbo-slskdVerified publisher0.3.01 of 1See more

slskd alexmorbo-slskd 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/slskd/slskd:0.25.1ab9ed50e028b
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6

Open the chart page →

1,779
tubearchivistalexmorbo-tubearchivistVerified publisher0.1.01 of 2See more

tubearchivist alexmorbo-tubearchivist 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
valkey/valkey:9.0.1546304417fea
pam@1.7.0-5
no fix listed

Open the chart page →

1,705
nginx-sni-proxyalexpressoVerified publisher1.0.21 of 1See more

nginx-sni-proxy alexpresso 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
pam@1.7.0-5
no fix listed

Open the chart page →

1,589
redisalexvanderberkelVerified publisher2.2.01 of 1See more

redis alexvanderberkel 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/redis:8.2.15fa2edb1e408
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

1,900
alibaba-rsocket-brokeralibaba-rsocket-brokerVerified publisher0.1.31 of 1See more

alibaba-rsocket-broker alibaba-rsocket-broker 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
linuxchina/alibaba-rsocket-broker:1.1.3-k8sf758e2e567ee
pam@1.1.8-3.6ubuntu2.18.04.3
no fix listed

Open the chart page →

89,955
allure-docker-helm-chartallure-service-chartVerified publisher0.1.01 of 2See more

allure-docker-helm-chart allure-service-chart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:latestdc171ec796d5
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6

Open the chart page →

3,744
katalogalpineworks0.1.21 of 5See more

katalog alpineworks 0.1.2

1 of the 5 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-migrations:v1.0.562c44a384e13
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

4,573
pagesalstom-pages-app1.0.02 of 3See more

pages alstom-pages-app 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
pam@1.3.1-5ubuntu4.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
pam@1.1.8-3.6ubuntu2.18.04.1
no fix listed

Open the chart page →

20,350
amorphieamorphie0.1.23 of 18See more

amorphie amorphie 0.1.2

3 of the 18 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
camunda/zeebe:8.4.5ab5abc09e407
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7
hazelcast/management-center:5.3.2f9d34300d330
pam@1.3.1-25.el8
0:1.3.1-40.el8_10
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
pam@1.4.0-11ubuntu2.3
1.4.0-11ubuntu2.7

Open the chart page →

28,511
anchore-admission-controlleranchore-charts0.9.01 of 2See more

anchore-admission-controller anchore-charts 0.9.0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
cfssl/cfssl:v1.6.5c9018c2ddf0b
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

7,641
music-assistant-serverandibraeuVerified publisher2.1.21 of 1See more

music-assistant-server andibraeu 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

5,800
stalwartandibraeuVerified publisher1.0.21 of 1See more

stalwart andibraeu 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
stalwartlabs/stalwart:v0.16.1425001929f36a
pam@1.7.0-5
no fix listed

Open the chart page →

1,632
pagesandrei-pages1.0.02 of 3See more

pages andrei-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
pam@1.3.1-5ubuntu4.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
pam@1.1.8-3.6ubuntu2.18.04.1
no fix listed

Open the chart page →

20,350
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
pam@1.1.8-3.6ubuntu2.18.04.6
no fix listed

Open the chart page →

11,662
mathesarandrenarchyVerified publisher1.8.01 of 1See more

mathesar andrenarchy 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
mathesar/mathesar:0.12.0091757cb01fe
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

7,204

Container images carrying it

2,505 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
pam@1.5.2-6+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
pam@1.5.2-6+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
pam@1.5.2-6+deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
pam@1.5.2-6+deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
pam@1.5.2-6+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.