Fedora · Extra Packages For Enterprise Linux · CVE-2026-19624
**Name of the Vulnerable Software and Affected Versions**
NetworkManager-l2tp (affected versions not specified)
**Description**
A flaw exists where the plugin writes attacker-controlled VPN connection properties, specifically `vpn.data` and `vpn.secrets` values, unescaped into a generated ipsec.conf file. Because pluto loads this file as root, a local unprivileged user can create and activate an L2TP VPN profile containing a newline-injected leftupdown directive. This allows pluto to execute the injected command as root during the establishment of the IKE security association, leading to local privilege escalation.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.