CVE-2026-54411Medium· 5.9▾ SunlitLinux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeate…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 10.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-63381Medium· 6.6Libevent is an event notification library
CVE-2026-55193High· 8.8FreeRDP is a free implementation of the Remote Desktop Protocol
CVE-2026-73066High· 7.1Tesseract is an open source OCR engine
CVE-2026-66373High· 7.5Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting…
CVE-2026-69247Medium· 5.9cryptography is a package designed to expose cryptographic primitives and recipes to Python developers
CVE-2023-0286High· 7.4openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286)