PT-2026-91409 · Fedora+3 · Extra Packages For Enterprise Linux+2

·

CVE-2026-19624

·

Published

2026-09-14

·

Updated

2026-09-26

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NetworkManager-l2tp (affected versions not specified)
Description A flaw exists where the plugin writes attacker-controlled VPN connection properties, specifically vpn.data and vpn.secrets values, unescaped into a generated ipsec.conf file. Because pluto loads this file as root, a local unprivileged user can create and activate an L2TP VPN profile containing a newline-injected leftupdown directive. This allows pluto to execute the injected command as root during the establishment of the IKE security association, leading to local privilege escalation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19624

Affected Products

Extra Packages For Enterprise Linux
Fedora
Networkmanager-L2Tp