MEDIUM
pam_usb: XPath injection via PAM-supplied identifiers in pam_usb configuration queries
Published May 27, 2026
6.5
MEDIUMCVSS 3.1
EPSS 0.41%
Description
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pam_usb builds XPath expressions from user-supplied identifiers (PAM username, service name) and device-supplied identifiers (USB device serial, model, vendor) to query /etc/pamusb.conf. These identifiers were not validated for XPath metacharacters, allowing injection of arbitrary XPath predicates. This vulnerability is fixed in 0.9.0.
Affected products
-
Affected
- < 0.9.0
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-32652 Advisory
- https://github.com/mcdope/pam_usb/commit/721fed08a3596cb5b4671ad702f8fdc12dcc7420 x_refsource_MISC
- https://github.com/mcdope/pam_usb/pull/311 x_refsource_MISC
- https://github.com/mcdope/pam_usb/security/advisories/GHSA-vfj3-5h5v-6g93 x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-32652 | Advisory | |
| https://github.com/mcdope/pam_usb/commit/721fed08a3596cb5b4671ad702f8fdc12dcc7420 | x_refsource_MISC | |
| https://github.com/mcdope/pam_usb/pull/311 | x_refsource_MISC | |
| https://github.com/mcdope/pam_usb/security/advisories/GHSA-vfj3-5h5v-6g93 | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 27, 2026
Updated May 28, 2026
Reserved May 18, 2026
Link CVE-2026-47273
CISA Vulnrichment
Updated May 28, 2026
Red Hat
No data
GitHub
No data