Junglewise Threat Intelligence

CVE-2026-47273: mcdope pam_usb XPath injection in configuration queries

CVE-2026-47273 · Severity: medium · CVSS 6.5 · Published 2026-05-27

Technologies: Mcdope Pam Usb. Vendors: Mcdope.

Executive brief

pam_usb is a tool that allows users to log into Linux systems using a USB drive as a physical key. A security flaw in how the tool processes usernames and device information could allow an attacker to bypass authentication checks. By using a specially crafted username or a modified USB device, an unauthorized person might gain access to the system by tricking the software into matching the wrong security profile.

Technical details

pam_usb prior to version 0.9.0 is vulnerable to XPath injection (CWE-91) within its configuration parser (src/conf.c). The software constructs XPath queries to /etc/pamusb.conf using unvalidated identifiers including the PAM username, service name, and USB device metadata (serial, model, vendor). An attacker can inject arbitrary XPath predicates by providing strings containing single-quotes or control characters. This can be achieved remotely via network services that use PAM (e.g., SSH) or locally by presenting a USB device with malicious hardware identifiers. Successful exploitation could allow an attacker to manipulate the authentication logic to match incorrect device entries or bypass device-specific security constraints. The vulnerability is fixed in version 0.9.0 by implementing a validator that rejects unsafe characters.

Affected products

  • mcdope pam_usb < 0.9.0

Timeline

  • 2026-05-14: patched: Fix merged into master branch via PR #311
  • 2026-05-20: advisory: GitHub Security Advisory published
  • 2026-05-27: disclosed: CVE-2026-47273 published to NVD

References

Related threats