CVE-2026-91840
Received Received - Intake

NetworkManager-vpnc Privilege Escalation via VPN Username Injection

Vulnerability report for CVE-2026-91840, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-25

Last updated on: 2026-09-25

Assigner: Fedora Project

Description

A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration to execute an arbitrary program with root privileges when the malicious VPN connection is activated.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-25
Last Modified
2026-09-25
Generated
2026-09-26
AI Q&A
2026-09-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
networkmanager vpnc *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-93 The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a local privilege escalation flaw in NetworkManager-vpnc. An attacker with local access but no special privileges can inject a newline character into the VPN username field. This manipulation allows them to alter the vpnc configuration so that when the malicious VPN connection is activated, an arbitrary program runs with root privileges.

Detection Guidance

To detect this vulnerability, inspect NetworkManager-vpnc configurations for malicious newline characters in VPN usernames. Check logs for unusual root privilege escalations during VPN connections. Review vpnc configuration files for injected commands or unexpected entries.

Impact Analysis

If you use NetworkManager-vpnc on a system, an attacker with local access could exploit this to gain full control of your system. They could install malware, steal data, or perform other malicious actions with root-level permissions.

Compliance Impact

This vulnerability allows local privilege escalation to root via manipulation of VPN credentials, which could lead to unauthorized access to sensitive data. Such access may violate compliance requirements under GDPR (data protection) or HIPAA (health information privacy) if exploited.

Mitigation Strategies

Update NetworkManager-vpnc to the latest patched version as soon as possible to address the privilege escalation flaw. Review VPN configurations for any suspicious entries, particularly in the username field where newline characters may have been injected. Restrict local user access to VPN configuration files and disable unnecessary VPN services until updates are applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91840. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart