CVE Explorer
CVE-2026-48981
pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, pam_usb calls xmlReadFile() with flags=0 when loading the configuration file, allowing libxml2 to process external entity references (XXE), potentially making outbound network connections or local file reads at XML parse time from the context of the authenticating process. The vulnerability requires the configuration file to contain crafted XML entity references. Since pam_usb.conf is r
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"pam_usb","vendor":"mcdope","versions":[{"status":"affected","version":"< 0.9.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:11f136ae6ed88c5f4861d1b3966bc1a671e1b33387b5ffca9e5b1028fa319afd · sha256:f7060e1c48110a40… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"LOW","baseScore":6.7,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:11f136ae6ed88c5f4861d1b3966bc1a671e1b33387b5ffca9e5b1028fa319afd · sha256:f7060e1c48110a40… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-611","description":"CWE-611: Improper Restriction of XML External Entity Reference","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:11f136ae6ed88c5f4861d1b3966bc1a671e1b33387b5ffca9e5b1028fa319afd · sha256:f7060e1c48110a40… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/mcdope/pam_usb/releases/tag/0.9.2","tags":["x_refsource_MISC"],"url":"https://github.com/mcdope/pam_usb/releases/tag/0.9.2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:11f136ae6ed88c5f4861d1b3966bc1a671e1b33387b5ffca9e5b1028fa319afd · sha256:f7060e1c48110a40… · /containers/cna/references/1
{"name":"https://github.com/mcdope/pam_usb/security/advisories/GHSA-96vv-r4wc-28c2","tags":["x_refsource_CONFIRM"],"url":"https://github.com/mcdope/pam_usb/security/advisories/GHSA-96vv-r4wc-28c2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:11f136ae6ed88c5f4861d1b3966bc1a671e1b33387b5ffca9e5b1028fa319afd · sha256:f7060e1c48110a40… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.