Executive brief
pam_usb is a tool that allows users to log into Linux systems using a USB drive as a physical key. A security flaw in how the tool processes usernames and device information could allow an attacker to bypass authentication checks. By using a specially crafted username or a modified USB device, an unauthorized person might gain access to the system by tricking the software into matching the wrong security profile.
Technical details
pam_usb prior to version 0.9.0 is vulnerable to XPath injection (CWE-91) within its configuration parser (src/conf.c). The software constructs XPath queries to /etc/pamusb.conf using unvalidated identifiers including the PAM username, service name, and USB device metadata (serial, model, vendor). An attacker can inject arbitrary XPath predicates by providing strings containing single-quotes or control characters. This can be achieved remotely via network services that use PAM (e.g., SSH) or locally by presenting a USB device with malicious hardware identifiers. Successful exploitation could allow an attacker to manipulate the authentication logic to match incorrect device entries or bypass device-specific security constraints. The vulnerability is fixed in version 0.9.0 by implementing a validator that rejects unsafe characters.
Affected products
- mcdope pam_usb < 0.9.0
Timeline
- 2026-05-14: patched: Fix merged into master branch via PR #311
- 2026-05-20: advisory: GitHub Security Advisory published
- 2026-05-27: disclosed: CVE-2026-47273 published to NVD