Junglewise Threat Intelligence

CVE-2026-48064: mcdope pam_usb incorrect authorization in remote host check

CVE-2026-48064 · Severity: high · CVSS 8.1 · Published 2026-05-27

Technologies: Mcdope Pam Usb. Vendors: Mcdope.

Executive brief

pam_usb is a tool that allows users to log into Linux systems using a physical USB drive as a security key. A flaw in how it handles remote connections allows attackers to bypass security checks that are supposed to ensure the user is physically present at the machine. If a system is configured to allow remote logins (such as via XDMCP), an attacker with a stolen or cloned USB device could potentially log in remotely, bypassing the intended physical security requirement.

Technical details

In pam_usb versions prior to 0.9.1, the PAM_RHOST check in the pusb_do_auth() function is incorrectly nested within a conditional block that only executes if 'deny_remote' is enabled. When 'deny_remote' is set to false (a common configuration for display managers like GDM or LightDM to avoid local TTY heuristic issues), the module fails to verify if the connection is originating from a remote host. This allows remote daemons that set PAM_RHOST, such as XDMCP or SSH, to proceed to the USB device authentication phase instead of being rejected. An attacker possessing a valid USB token and user credentials could exploit this to gain remote access to systems that were intended to only allow local USB-based logins. The issue is resolved in version 0.9.1 by decoupling the PAM_RHOST check from the 'deny_remote' configuration option.

Affected products

  • mcdope pam_usb < 0.9.1

Timeline

  • 2026-05-19: other: Issue first reported on GitHub
  • 2026-05-23: advisory: Project maintainer published security advisory GHSA-w38v-cw9r-x9p6
  • 2026-05-27: disclosed: CVE-2026-48064 published
  • 2026-05-27: patched: Fixed in version 0.9.1

References

Related threats