CVE-2026-48980
pam_usb provides hardware authentication for Linux using removable media. In versions prior to 0.9.2, getenv() environment variables XRDP_SESSION, DISPLAY and TMUX allow environment variable injection into local-check logic. These environment variables influence whether a current session is local or remote, and a PAM module that runs in the context of setuid binaries (sudo, su), getenv() returns attacker-controlled values whenever the process environment has been manipulated by a local user. This issue has been fixed in version 0.9.2.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 0.18%
- CWE
- CWE-454, CWE-807
- Published
- 2026-06-18
- Last modified
- 2026-06-20
Affected products
- mcdope pam_usb
Weakness type
Related vulnerabilities
- CVE-2026-54003 — Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
- CVE-2026-26148 — Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege Vulnerability
- CVE-2025-36244 — IBM AIX privilege escalation