CVE-2026-44711

HIGH

pam_usb: Symlink attacks on pad directory and pad files enable authentication bypass and root file corruption

Title source: cna
STIX 2.1

Description

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, symlink attacks on pad directory and pad files enable authentication bypass and root file corruption. This vulnerability is fixed in 0.8.7.

Scores

CVSS v3 7.9
EPSS 0.0017
EPSS Percentile 6.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-287 CWE-59
Status published
Products (1)
mcdope/pam_usb < 0.8.7
Published May 27, 2026
Tracked Since May 28, 2026