PT-2026-44109 · Pam Usb · Pam Usb

·

CVE-2026-44709

·

Published

2026-05-27

·

Updated

2026-05-28

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pam usb versions prior to 0.8.7
Description pam usb provides hardware authentication for Linux using removable media. The pamusb-pinentry component reads the PINENTRY FALLBACK APP environment variable and executes it without validation. A process capable of setting environment variables before pamusb-pinentry is invoked can point PINENTRY FALLBACK APP to an arbitrary binary or script, leading to execution with the privileges of the pam usb tool chain.
Recommendations Update to version 0.8.7.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44709
GHSA-JXRJ-Q67X-WR4C

Affected Products

Pam Usb