CVE-2026-91840: Networkmanager-vpnc: networkmanager-vpnc: local privilege escalation to root via newline injection in vpn username

Published Sep 15, 2026
·
Updated

A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration to execute an arbitrary program with root privileges when the malicious VPN connection is activated.

Other sources

A privilege escalation flaw was found in NetworkManager-vpnc, the vpnc VPN plugin for NetworkManager. nm-vpnc-service validates plugin-specific VPN configuration items for embedded newline characters, but omits the top-level NMSettingVpn user-name property from this check. This unvalidated username is later serialized verbatim into vpnc's configuration as an "Xauth username" directive. A local unprivileged user can create a VPN profile whose username contains a newline character followed by a "Password helper" directive, causing the root-privileged vpnc process to parse the injected directive and execute an attacker-chosen helper program with UID/EUID 0 when the malicious VPN connection is activated.

— Red Hat

Affected Software

1 affected component
NetworkManager NetworkManager-vpnc

Event History

Sep 15, 2026
Data Sourced
via Red Hat·09:51 AM
DescriptionSeverityAffected Software
Sep 25, 2026
CVE Published
via MITRE·05:56 PM
Data Sourced
via MITRE·05:56 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Systems using NetworkManager-vpnc are exposed if a local unprivileged user can create or modify a VPN connection profile and cause that connection to be activated. The described impact is local privilege escalation to root.

2

What does an attacker need to exploit it?

The attacker needs local unprivileged access and the ability to place a newline character in the VPN username field of a VPN connection. Exploitation occurs when the malicious VPN connection is activated.

3

How does successful exploitation affect the system?

A crafted VPN username can alter the generated vpnc configuration so that an arbitrary program is executed with root privileges. This can compromise confidentiality, integrity, and availability of the affected system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203