Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Keith Linneman

#35130of 57,584
7.8Total CVSS
Vulnerabilities · 1
PT-2026-91409
7.8
2026-09-14
Fedora · Extra Packages For Enterprise Linux · CVE-2026-19624
**Name of the Vulnerable Software and Affected Versions** NetworkManager-l2tp (affected versions not specified) **Description** A flaw exists where the plugin writes attacker-controlled VPN connection properties, specifically `vpn.data` and `vpn.secrets` values, unescaped into a generated ipsec.conf file. Because pluto loads this file as root, a local unprivileged user can create and activate an L2TP VPN profile containing a newline-injected leftupdown directive. This allows pluto to execute the injected command as root during the establishment of the IKE security association, leading to local privilege escalation. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.