CVE-2026-91840
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration to execute an arbitrary program with root privileges when the malicious VPN connection is activated.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GNOME | NetworkManager-vpnc | 0 < * | affected |
Weaknesses
- CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')
Workarounds
If vpnc VPN connections are not required, the NetworkManager-vpnc package can be removed to eliminate the vulnerability. This action will prevent the system from establishing vpnc-based VPN connections.
To remove the package, execute the following command as root:
# dnf remove NetworkManager-vpnc
Note that removing this package may impact functionality if vpnc VPNs are actively used.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: total
Additional References
References
- https://access.redhat.com/security/cve/CVE-2026-91840
- https://bugzilla.redhat.com/show_bug.cgi?id=2533642
- https://gitlab.gnome.org/Archive/NetworkManager-vpnc/-/work_items/19
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.