Junglewise Threat Intelligence

CVE-2026-44709: pam_usb command injection in pamusb-pinentry

CVE-2026-44709 · Severity: high · CVSS 7.8 · Published 2026-05-27

Technologies: Mcdope Pam Usb. Vendors: Mcdope.

Executive brief

pam_usb is a tool that allows users to log into Linux systems using USB drives or other removable media instead of just passwords. A security flaw in its PIN entry component allows a local attacker to run unauthorized commands or scripts with elevated system privileges. Additionally, a separate issue could allow other users on the same computer to briefly see sensitive keyring passwords during the login process.

Technical details

A command injection vulnerability exists in the pamusb-pinentry component of pam_usb due to the insecure handling of the PINENTRY_FALLBACK_APP environment variable. The application retrieves this variable and passes it directly to subprocess.run() without validation, allowing a local attacker who can influence the process environment to execute arbitrary binaries with the privileges of the pam_usb toolchain. Additionally, the pamusb-keyring-unlock-gnome component was found to interpolate GNOME Keyring passwords into shell command strings, making them visible in the process list (/proc/<pid>/cmdline). These issues are addressed in version 0.8.7 by implementing strict path validation for the fallback application and passing passwords via stdin.

Affected products

  • mcdope pam_usb < 0.8.7

Timeline

  • 2026-05-07: advisory: Original GitHub advisory published
  • 2026-05-27: disclosed: NVD publication date

References

Related threats