Description
A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration to execute an arbitrary program with root privileges when the malicious VPN connection is activated.
Published: 2026-09-25
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

If vpnc VPN connections are not required, the NetworkManager-vpnc package can be removed to eliminate the vulnerability. This action will prevent the system from establishing vpnc-based VPN connections. To remove the package, execute the following command as root: `# dnf remove NetworkManager-vpnc` Note that removing this package may impact functionality if vpnc VPNs are actively used.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 25 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration to execute an arbitrary program with root privileges when the malicious VPN connection is activated.
Title Networkmanager-vpnc: networkmanager-vpnc: local privilege escalation to root via newline injection in vpn username
Weaknesses CWE-93
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2026-09-25T18:15:12.060Z

Reserved: 2026-09-15T08:28:01.333Z

Link: CVE-2026-91840

cve-icon Vulnrichment

Updated: 2026-09-25T18:15:07.267Z

cve-icon NVD

Status : Received

Published: 2026-09-25T18:17:32.793

Modified: 2026-09-25T19:17:58.877

Link: CVE-2026-91840

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T20:30:17Z

Weaknesses