CVE-2026-54411
the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c vulnerability
Linux-PAM·Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.
MSRC advisory June 16, 2026
Alert details
- Source feed
- Microsoft MSRC
- CVE ID
- CVE-2026-54411
- Affected products
- Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext. · Linux-PAM Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext. · Linux-PAM
What happened
Information published.
What it means for your business
Linux-PAM Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext. (CVE-2026-54411) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Sources
Related briefs
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able N-central is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-18556). N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass. CISA remediation due date: 2026-08-07. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Apache Tomcat is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-34486). Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. CISA remediation due date: 2026-08-07. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Ongoing Threats of Swatting and Indicators for Community Members
Ongoing Threats of Swatting and Indicators for Community Members — FBI IC3 industry advisory relevant to cyber risk. PremierePC monitors federal alerts for Upstate SC businesses. Read the source link for full guidance or open a ticket if you want help assessing impact.
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able N-central is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-18577). N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556. CISA remediation due date: 2026-08-06. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Need help patching?
PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.