CVE-2026-91839

Description

A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local unprivileged user can exploit this by crafting a malicious VPN profile to inject additional configuration directives. This can lead to arbitrary code execution with root privileges when the crafted VPN connection is activated.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Mitigation

If the NetworkManager-fortisslvpn plugin is not required, remove the `NetworkManager-fortisslvpn` package to eliminate the attack vector.
To remove the package:
`sudo dnf remove NetworkManager-fortisslvpn`
This action may impact systems that rely on FortiSSLVPN connectivity. A system restart may be required for the changes to take full effect.

Understanding the Weakness (CWE)

Integrity

Technical Impact: Modify Application Data

Acknowledgements

Red Hat would like to thank Andreas Gabriel Berbescu for reporting this issue.

Frequently Asked Questions

Want to get errata notifications? Sign up here.