StackRadar

CVE-2026-54411

High

Advisory

Published 14 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,470
of 17,828 indexed, latest versions
Container images
2,505
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: pam security update

Carried by container images the latest versions of 2,470 of 17,828 indexed charts deploy, on 2,505 images.

Affected packageAffected versionsFixed inImages
pamdeb1.1.8-1ubuntu2, 1.1.8-1ubuntu2.2, 1.1.8-3.2ubuntu2, 1.1.8-3.2ubuntu2.1+33 more1.4.0-11ubuntu2.7, 1.5.3-5ubuntu5.6, 1.7.0-5+e5, 1.7.0-5ubuntu3.12,325
pamrpm1.1.8-22.el7, 1.1.8-23.el7, 1.3.0-150000.6.86.1, 1.3.0-lp151.7.38+29 more0:1.1.8-23.el7_9.3, 0:1.3.1-40.el8_10, 0:1.5.1-27.el9_8.1, 0:1.5.1-28.el9_8.1+4 more180
OSV records
DEBIAN-CVE-2026-54411RHSA-2026:56131RHSA-2026:59379RHSA-2026:60224RHSA-2026:61227RHSA-2026:64815RLSA-2026:56131RLSA-2026:59379RLSA-2026:64815UBUNTU-CVE-2026-54411ECHO-a8ba-b20f-6ddaopenSUSE-SU-2026:11201-1SUSE-SU-2026:22639-1SUSE-SU-2026:3163-1
Also known as
RHSA-2026:61223, RHSA-2026:61224, RHSA-2026:61225, RHSA-2026:61226, RHSA-2026:61228, RHSA-2026:61230, USN-8601-1

Charts affected

2,470 by stars
ChartLatestAffected imagesRadar Score
deepflowkubesphere-stable6.2.6062 of 8See more

deepflow kubesphere-stable 6.2.606

2 of the 8 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
pam@1.3.1-5ubuntu4.3
no fix listed
deepflowce/deepflow-agent:v6.2.6.529332fee7fc2
pam@1.4.0-11ubuntu2.3
1.4.0-11ubuntu2.7

Open the chart page →

18,588
iomeshkubesphere-stable1.1.04 of 25See more

iomesh kubesphere-stable 1.1.0

4 of the 25 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
iomesh/csi-driver:v2.7.25d3f9bf9240b
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7
iomesh/node-disk-exporter:1.8.0f03148764f38
pam@1.3.1-5ubuntu4.3
no fix listed
iomesh/node-disk-manager:1.8.0002c4b92fd34
pam@1.3.1-5ubuntu4.3
no fix listed
iomesh/node-disk-operator:1.8.0f6c76380db34
pam@1.3.1-5ubuntu4.3
no fix listed

Open the chart page →

49,169
IOMeshkubesphere-stable1.2.04 of 25See more

IOMesh kubesphere-stable 1.2.0

4 of the 25 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
iomesh/csi-driver:v2.8.01a151f602451
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7
iomesh/node-disk-exporter:1.8.0f03148764f38
pam@1.3.1-5ubuntu4.3
no fix listed
iomesh/node-disk-manager:1.8.0-2292ad270082e
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6
iomesh/node-disk-operator:1.8.0-1de4aa40684ad
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6

Open the chart page →

46,866
pulsarkubesphere-stable2.7.131 of 3See more

pulsar kubesphere-stable 2.7.13

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
pam@1.3.1-5ubuntu4.2
no fix listed

Open the chart page →

89,084
clickhousekubesphere-testVerified publisher0.1.11 of 2See more

clickhouse kubesphere-test 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
radondb/clickhouse-server:v21.1.3.32-stable4732df471073
pam@1.1.8-3.6ubuntu2.18.04.2
no fix listed

Open the chart page →

6,748
csi-neonsankubesphere-testVerified publisher1.3.01 of 6See more

csi-neonsan kubesphere-test 1.3.0

1 of the 6 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
csiplugin/csi-neonsan:v1.2.21fa83d45417f
pam@1.1.8-3.2ubuntu2.3
no fix listed

Open the chart page →

18,579
mongodbkubesphere-testVerified publisher0.3.21 of 2See more

mongodb kubesphere-test 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/mongo:4.2.16ca49afbcb2b
pam@1.1.8-3.6ubuntu2.18.04.1
no fix listed

Open the chart page →

9,672
mysqlkubesphere-testVerified publisher1.0.21 of 3See more

mysql kubesphere-test 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
xenondb/percona:5.7.330e26872a2b67
pam@1.3.1-5ubuntu4.1
no fix listed

Open the chart page →

7,427
sample-bookinfokubesphere-testVerified publisher1.0.01 of 4See more

sample-bookinfo kubesphere-test 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
kubesphere/examples-bookinfo-reviews-v2:1.13.06d93129beb32
pam@1.1.8-3.2ubuntu2.1
no fix listed

Open the chart page →

9,440
xenondbkubesphere-testVerified publisher1.0.01 of 3See more

xenondb kubesphere-test 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
xenondb/percona:5.7.330e26872a2b67
pam@1.3.1-5ubuntu4.1
no fix listed

Open the chart page →

7,427
vector-controllerkubevela0.2.31 of 2See more

vector-controller kubevela 0.2.3

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
oamdev/vector-controller:v0.2.39dd8be44ffc9
pam@1.1.8-3.6ubuntu2.18.04.6
no fix listed

Open the chart page →

4,843
kubevoipkubevoipOfficialVerified publisher0.6.81 of 1See more

kubevoip kubevoip 0.6.8

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/kubevoip/kubevoip:v0.6.841c603a93642
pam@1.7.0-5
no fix listed

Open the chart page →

1,127
kube-wordpress-mysqlkube-wordpress-mysql0.1.01 of 2See more

kube-wordpress-mysql kube-wordpress-mysql 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/wordpress:php8.1-apachef73396626d2f
pam@1.7.0-5
no fix listed

Open the chart page →

8,938
penpotkubitodevVerified publisher1.2.12 of 5See more

penpot kubitodev 1.2.1

2 of the 5 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
penpotapp/backend:2.2.147853d9bb9dd
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7
penpotapp/exporter:2.2.15c835ffd87ab
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7

Open the chart page →

17,333
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.43 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

3 of the 9 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
grafana/alloy:v1.5.101a63f4e032c
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
pam@1.7.0-5
no fix listed
ghcr.io/kubiyabot/kubernetes:1.32.0b5ade0d9cc6b
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

20,605
ctrlmeshkusionstackVerified publisher0.2.01 of 1See more

ctrlmesh kusionstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
kusionstack/ctrlmesh-manager:v0.2.065e3c32b64d7
pam@1.3.1-5ubuntu4.7
no fix listed

Open the chart page →

3,510
kusionkusionstackVerified publisher0.14.11 of 3See more

kusion kusionstack 0.14.1

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
kusionstack/kusion:v0.14.0126c8f0b0976
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7

Open the chart page →

62,114
sample-operatorkusionstackVerified publisher0.1.21 of 1See more

sample-operator kusionstack 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
chaerr/kridge:demo-operator-v0.1.266833deec017
pam@1.3.1-5ubuntu4.6
no fix listed

Open the chart page →

2,543
fstyr-ddp-keycloak-application-platform-configkvalitetsitVerified publisher0.1.131 of 1See more

fstyr-ddp-keycloak-application-platform-config kvalitetsit 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6

Open the chart page →

3,207
keycloak-application-platform-configkvalitetsitVerified publisher0.0.291 of 1See more

keycloak-application-platform-config kvalitetsit 0.0.29

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6

Open the chart page →

3,438
longhornkvalitetsitVerified publisher1.1.1-01 of 2See more

longhorn kvalitetsit 1.1.1-0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.1.1ede61fe2a472
pam@1.1.8-3.6ubuntu2.18.04.2
no fix listed

Open the chart page →

16,771
stakitkvalitetsitVerified publisher0.3.111 of 3See more

stakit kvalitetsit 0.3.11

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7

Open the chart page →

7,898
nginx-chartkyb-nginx0.1.01 of 1See more

nginx-chart kyb-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
pam@1.7.0-5
no fix listed

Open the chart page →

1,965
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
kubeoperator/webkubectl:v2.4.0be8f0d624640
pam@1.1.8-3.6ubuntu2.18.04.1
no fix listed

Open the chart page →

26,597
pageslatif-pages1.0.02 of 3See more

pages latif-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
pam@1.3.1-5ubuntu4.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
pam@1.1.8-3.6ubuntu2.18.04.1
no fix listed

Open the chart page →

20,350
pageslavanya-pages1.0.02 of 3See more

pages lavanya-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
pam@1.3.1-5ubuntu4.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
pam@1.1.8-3.6ubuntu2.18.04.1
no fix listed

Open the chart page →

20,350
smtplbenicio-communityVerified publisher0.1.31 of 1See more

smtp lbenicio-community 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
pam@1.7.0-5
no fix listed

Open the chart page →

1,414
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

33,939
jenkinsleechistest2.7.11 of 2See more

jenkins leechistest 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
pam@1.7.0-5
no fix listed

Open the chart page →

4,493
kinesaliteleprechaun-charts0.1.21 of 1See more

kinesalite leprechaun-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
instructure/kinesalite:latest34400d82f28f
pam@1.3.1-5ubuntu4.7
no fix listed

Open the chart page →

4,316
owntracks-exporterleprechaun-charts0.1.111 of 1See more

owntracks-exporter leprechaun-charts 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/leprechaun/owntracks-exporter:0.1.11-de545066099e1abd6d08
pam@1.5.2-6
no fix listed

Open the chart page →

4,104
vaultwardenleprechaun-charts0.1.281 of 1See more

vaultwarden leprechaun-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.1ebdfe70701c6
pam@1.7.0-5
no fix listed

Open the chart page →

2,081
jackettlib42Verified publisher1.1.01 of 1See more

jackett lib42 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
lib42/jackett:latesta55596cda383
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

4,678
libredb-studiolibredb-studio-oci0.1.671 of 1See more

libredb-studio libredb-studio-oci 0.1.67

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/libredb/libredb-studio:0.16.2c398419c29a7
pam@1.7.0-5
no fix listed

Open the chart page →

1,198
librenmslibrenms10.1.21 of 5See more

librenms librenms 10.1.2

1 of the 5 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/redis:8.10.1602d361c4da9
pam@1.7.0-5
no fix listed

Open the chart page →

2,743
kube-iptables-tailerlifen0.2.31 of 1See more

kube-iptables-tailer lifen 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
pam@1.3.1-5ubuntu4.3
no fix listed

Open the chart page →

4,501
lightlyticslightlytics0.1.212 of 2See more

lightlytics lightlytics 0.1.21

2 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
pam@1.5.2-6+deb12u1
no fix listed
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

5,453
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

38,690
weblinzhengen0.1.71 of 1See more

web linzhengen 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
pam@1.7.0-5
no fix listed

Open the chart page →

1,965
listmonklistmonk-chartVerified publisher2.0.11 of 2See more

listmonk listmonk-chart 2.0.1

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/postgres:15dfbbb0ad8cab
pam@1.7.0-5
no fix listed

Open the chart page →

2,712
pocketbase-halitesql0.0.31 of 1See more

pocketbase-ha litesql 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/litesql/pocketbase-ha:latestc5b28608958b
pam@1.7.0-5
no fix listed

Open the chart page →

1,168
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
pam@1.4.0-11ubuntu2.3
1.4.0-11ubuntu2.7

Open the chart page →

10,874
pagesliviu884422-pages1.0.02 of 3See more

pages liviu884422-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
pam@1.3.1-5ubuntu4.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
pam@1.1.8-3.6ubuntu2.18.04.1
no fix listed

Open the chart page →

20,350
web-chartljw-ktcloudlab0.1.01 of 1See more

web-chart ljw-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
pam@1.7.0-5
no fix listed

Open the chart page →

1,589
llmarinerllmariner1.53.11 of 21See more

llmariner llmariner 1.53.1

1 of the 21 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
pam@1.7.0-5
no fix listed

Open the chart page →

13,114
llm-dllm-dVerified publisher1.0.231 of 2See more

llm-d llm-d 1.0.23

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/llm-d/llm-d-model-service:v0.0.158b99a8104a2f
pam@1.5.1-23.el9
0:1.5.1-27.el9_8.1

Open the chart page →

2,565
jellyfinlmatfyVerified publisher0.1.31 of 1See more

jellyfin lmatfy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11aefb67e6a7ff
pam@1.7.0-5
no fix listed

Open the chart page →

2,681
mt-mcp-grafanaloafoe0.10.01 of 2See more

mt-mcp-grafana loafoe 0.10.0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
grafana/mcp-grafana:0.14.042f541f22063
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

1,986
locust-pluginslocust-pluginsVerified publisher0.0.41 of 3See more

locust-plugins locust-plugins 0.0.4

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
locustio/locust:2.24.151d866285170
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

7,583
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

33,939

Container images carrying it

2,505 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
pam@1.5.2-6+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
pam@1.5.2-6+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
pam@1.5.2-6+deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
pam@1.5.2-6+deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
pam@1.5.2-6+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.