CVE-2026-91838: Networkmanager-sstp: networkmanager-sstp: local privilege escalation to root via shell injection in vpn profile fields

Published Sep 15, 2026
·
Updated

A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields such as CA certificate or proxy settings. These unescaped characters are then processed by the pppd daemon, which runs with root privileges, allowing the attacker to execute arbitrary commands with elevated permissions when a malicious VPN connection is activated.

Affected Software

1 affected component
NetworkManager NetworkManager-sstp

Event History

Sep 15, 2026
Data Sourced
via Red Hat·09:41 AM
DescriptionSeverityAffected Software
Sep 25, 2026
CVE Published
via MITRE·05:51 PM
Data Sourced
via MITRE·05:51 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this vulnerability?

A local unprivileged user who can create or modify an SSTP VPN connection profile with attacker-controlled fields is exposed. The issue is triggered when the malicious VPN connection is activated.

2

What profile settings are relevant to exploitation?

The affected input includes VPN profile fields such as the CA certificate or proxy settings. Shell metacharacters placed in these fields can be processed by pppd.

3

Why does successful exploitation result in root access?

pppd processes the unescaped profile values while running with root privileges. This allows commands injected through the malicious profile to execute with elevated permissions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203