pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pam_usb builds XPath expressions from user-supplied identifiers (PAM username, service name) and device-supplied identifiers (USB device serial, model, vendor) to query /etc/pamusb.conf. These identifiers were not validated for XPath metacharacters, allowing injection of arbitrary XPath predicates. This vulnerability is fixed in 0.9.0.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-91"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47273.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47273.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "310671743499104942899270600637756684978",
"length": 3256
},
"id": "CVE-2026-47273-298ef5f8",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/mcdope/pam_usb/commit/721fed08a3596cb5b4671ad702f8fdc12dcc7420",
"target": {
"file": "src/conf.c",
"function": "pusb_conf_parse"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "270339150120948850787340306911047059359",
"length": 983
},
"id": "CVE-2026-47273-2b5b8797",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/mcdope/pam_usb/commit/721fed08a3596cb5b4671ad702f8fdc12dcc7420",
"target": {
"file": "src/conf.c",
"function": "pusb_conf_parse_options"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"246701530795718054760766359822102673647",
"163762952215095569774013772477832971739",
"232920681140646834693481693883826096748",
"149123065363384387112896112448975769662",
"46030852730075528956880356551658173343",
"221692598311262703710387801666091038650",
"81119492962989446877264989511180895977",
"232754034174691913719913256377319797327",
"216403504657403822020051177198098062289",
"88261366851343081187507998116848401570",
"141570330148475992474461485091056110662",
"233306314831964105930273343958581142593",
"96316546211728756959196745729648594453",
"126373424467606256217501060288548317469",
"30731470253983092546416543921991702255",
"230854825460418152943838715776612367349",
"144392624317396963876230002699789657553",
"233455148104437129001283558095861668116",
"89186948063608796069460967015909564041",
"205821891032032800981083820920145737526",
"5860235293892562734799130018079360840",
"201572138625204470285921500174429956175",
"41513266089693530692957876566759078435",
"14387766747173061755923643574437896863",
"209804995111564432711134090228489579826",
"76327817457152540844180179744807252129"
],
"threshold": 0.9
},
"id": "CVE-2026-47273-4312013f",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/mcdope/pam_usb/commit/721fed08a3596cb5b4671ad702f8fdc12dcc7420",
"target": {
"file": "src/conf.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"95018822407014656935460510796658212673",
"47101078584502193039357696094212759993",
"264918043665150147099799319676081503424",
"324404316164409777832522250046887967703",
"324835129630636283794632081393875026441"
],
"threshold": 0.9
},
"id": "CVE-2026-47273-51f9deb6",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/mcdope/pam_usb/commit/721fed08a3596cb5b4671ad702f8fdc12dcc7420",
"target": {
"file": "src/conf.h"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "114404690382973049510279634202138577957",
"length": 706
},
"id": "CVE-2026-47273-7ecbc5de",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/mcdope/pam_usb/commit/721fed08a3596cb5b4671ad702f8fdc12dcc7420",
"target": {
"file": "src/conf.c",
"function": "pusb_conf_parse_device"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"108488775856077732286113317730806169097",
"139738535580040197364407161876476359964",
"246920428864091627321906287672152200746",
"16778275172920344388998912056505594634",
"52599055438210507981449592238404711868",
"203939871491460022887287174427359917849",
"40737150561407681921634740536880617377"
],
"threshold": 0.9
},
"id": "CVE-2026-47273-98e61752",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/mcdope/pam_usb/commit/721fed08a3596cb5b4671ad702f8fdc12dcc7420",
"target": {
"file": "tests/unit/c/conf_test.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "149155048978678720489076900114457885412",
"length": 747
},
"id": "CVE-2026-47273-edda70a9",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/mcdope/pam_usb/commit/721fed08a3596cb5b4671ad702f8fdc12dcc7420",
"target": {
"file": "tests/unit/c/conf_test.c",
"function": "main"
}
}
]
"2026-08-12T16:09:40Z"