CVE-2026-91840
Description
A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration to execute an arbitrary program with root privileges when the malicious VPN connection is activated.
Statement
Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.
Mitigation
If vpnc VPN connections are not required, the NetworkManager-vpnc package can be removed to eliminate the vulnerability. This action will prevent the system from establishing vpnc-based VPN connections.
To remove the package, execute the following command as root:
`# dnf remove NetworkManager-vpnc`
Note that removing this package may impact functionality if vpnc VPNs are actively used.
Understanding the Weakness (CWE)
Integrity
Technical Impact: Modify Application Data
Acknowledgements
Red Hat would like to thank Andreas Gabriel Berbescu for reporting this issue.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.