CVE-2026-91838
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields such as CA certificate or proxy settings. These unescaped characters are then processed by the pppd daemon, which runs with root privileges, allowing the attacker to execute arbitrary commands with elevated permissions when a malicious VPN connection is activated.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GNOME | NetworkManager-sstp | 0 < * | affected |
Weaknesses
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Workarounds
The vulnerability requires a local unprivileged user to activate a malicious VPN connection. If the NetworkManager-sstp package is not required, removing it will eliminate the attack vector.
To remove the NetworkManager-sstp package:
sudo dnf remove NetworkManager-sstp
This action may impact functionality that relies on SSTP VPN connections.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
Additional References
References
- https://access.redhat.com/security/cve/CVE-2026-91838
- https://bugzilla.redhat.com/show_bug.cgi?id=2533637
- https://gitlab.gnome.org/GNOME/network-manager-sstp/-/work_items/67
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.