CVE-2026-93337: NetworkManager-l2tp Privilege Escalation via pppd Plugin Injection

Published Sep 17, 2026
·
Updated

NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu property values containing trailing non-numeric content after a valid integer. Attackers can exploit the verbatim write of unvalidated strings into the pppd options file via writeconfigoption() to inject the plugin directive, causing the privileged pppd process to load an attacker-controlled shared object and achieve arbitrary code execution as root.

Affected Software

1 affected component
NetworkManager-l2tp

Event History

Sep 17, 2026
CVE Published
via MITRE·07:17 PM
Data Sourced
via MITRE·07:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

A local user who has permission to create VPN connections can exploit it. Exploitation requires that the user can supply crafted mru or mtu property values.

2

What access does successful exploitation provide?

Successful exploitation can cause the privileged pppd process to load an attacker-controlled shared object. This results in arbitrary code execution as root.

3

What input is used to trigger the injection?

The attacker supplies an mru or mtu value consisting of a valid integer followed by non-numeric trailing content. That content is written verbatim into the pppd options file and can inject a pppd plugin directive.

4

How can I determine whether a system may be exposed?

A system may be exposed if it uses NetworkManager-l2tp and allows local users to create VPN connections. Review whether such users can set mru or mtu properties for those connections.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203