Technology · Mcdope
Mcdope Pam Usb vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 22 vulnerabilities in Mcdope Pam Usb: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-48983, was published on 18 June 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
About Mcdope Pam Usb
A PAM module that provides hardware authentication using ordinary USB flash drives.
Latest Mcdope Pam Usb vulnerabilities
- CVE-2026-48983: mcdope pam_usb symlink race condition in pad directory creationmediumCVSS 5.8
- CVE-2026-48982: mcdope pam_usb race condition in one-time pad updatemediumCVSS 5.8
- CVE-2026-48981: mcdope pam_usb XXE in configuration file parsingmediumCVSS 6.7
- CVE-2026-48980: mcdope pam_usb environment variable injection in local-check logicmediumCVSS 6.3
- CVE-2026-48986: mcdope pam_usb infinite loop DoS in process-tree walkmediumCVSS 4.7
- CVE-2026-48985: mcdope pam_usb NULL pointer dereference in pusb_is_loginctl_localmediumCVSS 5.5
- CVE-2026-48984: mcdope pam_usb sensitive information disclosure in xfree helpermediumCVSS 4.7
- CVE-2026-47270: pam_usb race condition in remote session detectionmediumCVSS 6.3
- CVE-2026-47269: mcdope pam_usb access control bypass in deny_remotehighCVSS 7.4
- CVE-2026-44713: mcdope pam_usb command injection in tmux.chighCVSS 8.8
- CVE-2026-44712: mcdope pam_usb command injection in pamusb-conf and pamusb-agenthighCVSS 8.2
- CVE-2026-44711: mcdope pam_usb authentication bypass and file corruption via symlink attackhighCVSS 7.9
- CVE-2026-44710: pam_usb NULL pointer dereference in device enumerationmediumCVSS 4.6
- CVE-2026-44709: pam_usb command injection in pamusb-pinentryhighCVSS 7.8
- CVE-2026-48792: mcdope pam_usb protection mechanism failure in virtual device detectionmediumCVSS 4.4
- CVE-2026-48066: mcdope pam_usb race condition in log.cmediumCVSS 5.7
- CVE-2026-48065: mcdope pam_usb heap overflow in conf.c on 32-bit systemsmediumCVSS 6.7
- CVE-2026-48064: mcdope pam_usb incorrect authorization in remote host checkhighCVSS 8.1
- CVE-2026-47274: mcdope pam_usb uncontrolled search path in helper toolsmediumCVSS 6.3
- CVE-2026-47273: mcdope pam_usb XPath injection in configuration queriesmediumCVSS 6.5
- CVE-2026-47272: pam_usb authentication bypass in pusb_pad_comparehighCVSS 7.1
- CVE-2026-47271: mcdope pam_usb NULL pointer dereference in src/mem.cmediumCVSS 5.1
Most severe Mcdope Pam Usb vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-44713: mcdope pam_usb command injection in tmux.chighCVSS 8.8
- CVE-2026-44712: mcdope pam_usb command injection in pamusb-conf and pamusb-agenthighCVSS 8.2
- CVE-2026-48064: mcdope pam_usb incorrect authorization in remote host checkhighCVSS 8.1
- CVE-2026-44711: mcdope pam_usb authentication bypass and file corruption via symlink attackhighCVSS 7.9
- CVE-2026-44709: pam_usb command injection in pamusb-pinentryhighCVSS 7.8
- CVE-2026-47269: mcdope pam_usb access control bypass in deny_remotehighCVSS 7.4
- CVE-2026-47272: pam_usb authentication bypass in pusb_pad_comparehighCVSS 7.1
- CVE-2026-48981: mcdope pam_usb XXE in configuration file parsingmediumCVSS 6.7
- CVE-2026-48065: mcdope pam_usb heap overflow in conf.c on 32-bit systemsmediumCVSS 6.7
- CVE-2026-47273: mcdope pam_usb XPath injection in configuration queriesmediumCVSS 6.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/pam-usb.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Mcdope Pam Usb vulnerabilities", https://junglewise.ai/threats/technologies/pam-usb, 26 September 2026.