PT-2026-44109 · Pam Usb · Pam Usb

Mcdope

·

Published

2026-05-27

·

Updated

2026-05-28

·

CVE-2026-44709

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pam usb versions prior to 0.8.7
Description pam usb provides hardware authentication for Linux using removable media. The pamusb-pinentry component reads the PINENTRY FALLBACK APP environment variable and executes it without validation. A process capable of setting environment variables before pamusb-pinentry is invoked can point PINENTRY FALLBACK APP to an arbitrary binary or script, leading to execution with the privileges of the pam usb tool chain.
Recommendations Update to version 0.8.7.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-44709

Affected Products

Pam Usb