CVE-2026-19624: NetworkManager-l2tp: local privilege escalation via ipsec.conf injection

Published Sep 14, 2026
·
Updated

A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged user can create and activate their own L2TP VPN profile containing a newline-injected leftupdown directive; pluto executes that command as root when the IKE security association is established, resulting in local privilege escalation. This is the same bug class as CVE-2018-10900 (NetworkManager-vpnc).

Affected Software

1 affected component
NetworkManager-l2tp

Event History

Sep 14, 2026
CVE Published
via MITRE·07:19 PM
Data Sourced
via MITRE·07:19 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

A local unprivileged user who can create and activate their own L2TP VPN profile can exploit the flaw. Exploitation requires the user to supply crafted VPN connection properties containing a newline-injected leftupdown directive.

2

What component executes the injected command?

NetworkManager-l2tp writes the attacker-controlled values into a generated ipsec.conf file. Pluto loads that file as root and executes the injected command when the IKE security association is established.

3

How can I determine whether a system may be vulnerable?

A system may be affected if it uses NetworkManager-l2tp and permits a local unprivileged user to create and activate L2TP VPN profiles. The described attack depends on attacker-controlled vpn.data or vpn.secrets values being written unescaped into ipsec.conf.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203