CVE-2026-3184
A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.
Scoring
- Severity
- LOW
- CVSS base score
- 3.7
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS probability
- 0.44%
- CWE
- CWE-289
- Published
- 2026-04-03
- Last modified
- 2026-09-14
Affected products
- Red Hat Red Hat Hardened Images
Weakness type
Related vulnerabilities
- CVE-2021-34746 — Cisco Enterprise NFV Infrastructure Software Authentication Bypass Vulnerability
- CVE-2025-29266 — Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication
- CVE-2024-56511 — DataEase has an unauthorized vulnerability
- CVE-2023-20046 — A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remot
- CVE-2026-8457 — WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT
- CVE-2026-15980 — MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token
- CVE-2025-13613 — Elated Membership <= 1.2 - Authentication Bypass via Social Login
- CVE-2026-9701 — Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation