Junglewise Threat Intelligence

CVE-2026-47274: mcdope pam_usb uncontrolled search path in helper tools

CVE-2026-47274 · Severity: medium · CVSS 6.3 · Published 2026-05-27

Technologies: Mcdope Pam Usb. Vendors: Mcdope.

Executive brief

pam_usb is a tool that allows users to log into Linux systems using a USB drive instead of a password. A security flaw in several of its helper tools allows an attacker with local access to trick the system into running malicious programs instead of legitimate system utilities. This could lead to an attacker gaining unauthorized access to sensitive data or elevated system privileges.

Technical details

Multiple helper tools in pam_usb, including pamusb-check, pamusb-conf, and pamusb-keyring-unlock-gnome, resolve external binaries (such as tmux, findmnt, and id) using the PATH environment variable rather than absolute paths. An attacker who can influence the process environment during PAM authentication or tool execution can substitute malicious binaries to achieve local privilege escalation. Additionally, pamusb-keyring-unlock-gnome was found to source password files using shell eval and pass passwords via command-line arguments, further increasing the risk of credential exposure. These issues are addressed in version 0.9.0 by using absolute paths and reading password files as data.

Affected products

  • mcdope pam_usb < 0.9.0

Timeline

  • 2026-05-17: patched: Fixes committed to repository
  • 2026-05-20: advisory: GitHub Security Advisory published
  • 2026-05-27: disclosed: CVE published to NVD

References

Related threats