


Perceptive Security
SOC/SIEM Consultancy

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, pamusb-pinentry reads the PINENTRY_FALLBACK_APP environment v…
Published:
26 mei 2026 om 22:00:00
Alert date:
27 mei 2026 om 22:02:45
Source:
nvd.nist.gov
Operating Systems, Identity & Access
A vulnerability in pam_usb prior to version 0.8.7 allows arbitrary code execution through the PINENTRY_FALLBACK_APP environment variable. The pamusb-pinentry component executes the content of this environment variable without validation, enabling privilege escalation attacks. Any process that can set environment variables before pamusb-pinentry execution can exploit this flaw to run arbitrary binaries with pam_usb privileges. This affects the hardware authentication system for Linux that uses removable media for authentication.
Technical details
Mitigation steps:
Affected products:
pam_usb
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44709
https://github.com/mcdope/pam_usb/security/advisories/GHSA-jxrj-q67x-wr4c
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
