CVE-2020-27780: Linux-Pam

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't exist PAM try to authenticate with root and in the case of an empty password it successfully authenticate.

Affected products

  • Linux-Pam Linux-Pam: from 1.5.0, before 1.5.1 (fixed in 1.5.1)

Published 2020-12-18. Last modified 2026-06-17.