CVE-2026-91839

Summary

A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local unprivileged user can exploit this by crafting a malicious VPN profile to inject additional configuration directives. This can lead to arbitrary code execution with root privileges when the crafted VPN connection is activated.

Affected Software

VendorProductVersion RangeStatus
GNOMENetworkManager-fortisslvpn0 < *affected

Weaknesses

  • CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')

Workarounds

If the NetworkManager-fortisslvpn plugin is not required, remove the NetworkManager-fortisslvpn package to eliminate the attack vector. To remove the package: sudo dnf remove NetworkManager-fortisslvpn This action may impact systems that rely on FortiSSLVPN connectivity. A system restart may be required for the changes to take full effect.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: total

Additional References

References