Junglewise Threat Intelligence

CVE-2026-47269: mcdope pam_usb access control bypass in deny_remote

CVE-2026-47269 · Severity: high · CVSS 7.4 · Published 2026-05-27

Technologies: Mcdope Pam Usb. Vendors: Mcdope.

Executive brief

pam_usb is a tool that allows users to log into Linux systems using a physical USB drive as a security key. A flaw in its remote-access protection allows attackers to bypass security restrictions when connecting over a network via SSH. If an attacker has physical access to a registered USB device, they can use it to log into a remote server even if the system is configured to block remote USB authentication, potentially leading to unauthorized access to sensitive data and systems.

Technical details

A vulnerability exists in pam_usb's 'deny_remote' feature due to an incomplete check of the utmpx ut_addr_v6 field. The software originally only validated the first 32-bit word of the 128-bit IPv6 address field to detect remote sessions. Because IPv4-mapped IPv6 addresses (::ffff:x.x.x.x) store the address data in the final word and leave the first word as zero, remote connections on systems using IPv6 wildcards (common in Debian/Ubuntu SSH configurations) are misclassified as local. An attacker with physical access to a registered USB device can exploit this to authenticate via SSH, bypassing the intended remote-access block. This issue is resolved in version 0.9.0 by ensuring all four words of the address field are checked.

Affected products

  • mcdope pam_usb < 0.9.0

Timeline

  • 2026-05-20: advisory: GitHub Security Advisory published
  • 2026-05-27: disclosed: CVE-2026-47269 published to NVD
  • 2026-05-27: patched: Fixed in version 0.9.0

References

Related threats