CVE-2026-19624

Summary

A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged user can create and activate their own L2TP VPN profile containing a newline-injected leftupdown directive; pluto executes that command as root when the IKE security association is established, resulting in local privilege escalation. This is the same bug class as CVE-2018-10900 (NetworkManager-vpnc).

Affected Software

VendorProductVersion RangeStatus
1.0.0 < 1.0.16affected
1.2.0 < 1.2.22affected
1.8.0 < 1.8.10affected
1.20.0 < 1.20.24affected
1.52.0 < 1.52.4affected
FedoraFedora1.52.0 < 1.52.4affected
FedoraExtra Packages for Enterprise Linux (EPEL)1.20.0 < 1.20.24affected

Weaknesses

  • CWE-88: Improper Control of an Argument of a Program Call ('Argument Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References