CVE-2026-91841
Description
A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by injecting a newline character into the CA-File path. This manipulation allows the user to execute arbitrary commands as the root user, leading to local privilege escalation.
Statement
Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.
Mitigation
To mitigate this issue, remove the `NetworkManager-vpnc` package if the vpnc VPN plugin functionality is not required on the system. This will prevent a local unprivileged user from exploiting the flaw.
To remove the package, use the following command:
`sudo dnf remove NetworkManager-vpnc`
Note that removing this package will disable the ability to use vpnc-based VPN connections.
Understanding the Weakness (CWE)
Integrity
Technical Impact: Modify Application Data
Acknowledgements
Red Hat would like to thank Andreas Gabriel Berbescu for reporting this issue.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.