Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 02 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mcdope
Mcdope pam Usb |
|
| Vendors & Products |
Mcdope
Mcdope pam Usb |
Wed, 27 May 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, pamusb-pinentry reads the PINENTRY_FALLBACK_APP environment variable and executes it directly without any validation. Any process that can set environment variables before pamusb-pinentry is invoked can point PINENTRY_FALLBACK_APP at an arbitrary binary or script and have it executed with the privileges of the pam_usb tool chain. This vulnerability is fixed in 0.8.7. | |
| Title | pam_usb: PINENTRY_FALLBACK_APP environment variable allows arbitrary command execution | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-02T17:59:08.656Z
Reserved: 2026-05-07T17:07:09.318Z
Link: CVE-2026-44709
Updated: 2026-06-02T17:56:42.616Z
Status : Deferred
Published: 2026-05-27T21:16:17.807
Modified: 2026-06-17T10:51:15.500
Link: CVE-2026-44709
No data.
OpenCVE Enrichment
Updated: 2026-05-29T15:49:54Z