Unknown · Networkmanager-L2Tp · CVE-2026-93337
**Name of the Vulnerable Software and Affected Versions**
NetworkManager-l2tp (affected versions not specified)
**Description**
Improper input validation allows local users with VPN connection creation permissions to inject arbitrary pppd directives. By providing `mru` or `mtu` property values that contain non-numeric content following a valid integer, an attacker can exploit the `write config option()` function, which writes unvalidated strings directly into the pppd options file. This allows the injection of a plugin directive, leading the privileged pppd process to load a malicious shared object and execute arbitrary code with root privileges.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.