PT-2026-86594 · Canonical · Pam

Published

2026-08-27

·

Updated

2026-08-27

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Juthawong Naisanguansee discovered that PAM incorrectly cleared failed login attempt records when certain services invoked the account phase without first performing authentication. An attacker could possibly use this issue to reset failed login counters, resulting in authentication lockout restrictions being bypassed.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

USN-8688-1

Affected Products

Pam