Junglewise Threat Intelligence

CVE-2026-47272: pam_usb authentication bypass in pusb_pad_compare

CVE-2026-47272 · Severity: high · CVSS 7.1 · Published 2026-05-27

Technologies: Mcdope Pam Usb. Vendors: Mcdope.

Executive brief

pam_usb is a tool that allows users to log into Linux systems using a physical USB drive as a security key. A flaw in how the software checks for these security keys allows a local user to bypass the hardware requirement entirely by deleting a specific file in their home directory. This effectively disables the multi-factor authentication, allowing unauthorized access to the system without the required physical USB device.

Technical details

The vulnerability exists in the pusb_pad_compare() function within src/pad.c of pam_usb. The function fails to enforce that the system-side pad (stored on the USB device) is present and readable, only verifying the user-side pad (~/.pamusb/device.pad). If the user-side pad is missing or unreadable, the function returns a failure that is treated as non-fatal in certain code paths, allowing authentication to proceed without verifying the physical hardware. Additionally, a secondary issue involves the use of uninitialized stack memory when generating random pads if /dev/random fails to provide sufficient bytes. These issues are addressed in version 0.9.0 by implementing symmetrical pad verification and switching to getrandom(2).

Affected products

  • mcdope pam_usb < 0.9.0

Timeline

  • 2026-05-20: advisory: GitHub Security Advisory published
  • 2026-05-27: disclosed: CVE published to NVD

References

Related threats