CVE-2026-91841: Networkmanager-vpnc: networkmanager-vpnc: incomplete fix for cve-2018-10900 allows root privilege escalation via ca-file path newline injection
Published Sep 25, 2026
·Updated
A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by injecting a newline character into the CA-File path. This manipulation allows the user to execute arbitrary commands as the root user, leading to local privilege escalation.
Affected Software
1 affected component
NetworkManager NetworkManager-vpnc
Event History
Sep 25, 2026
CVE Published
via MITRE·05:56 PM
Data Sourced
via MITRE·05:56 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A local unprivileged user can exploit it. The attack requires local access and low privileges; no user interaction is required.
2
What access does successful exploitation provide?
Successful exploitation allows arbitrary command execution as the root user, resulting in full local privilege escalation.
3
What input is used to trigger the vulnerability?
The attacker injects a newline character into the CA-File path used by the NetworkManager-vpnc plugin.