PT-2026-95076 · Unknown · Networkmanager-L2Tp

·

CVE-2026-93337

·

Published

2026-09-17

·

Updated

2026-09-18

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions NetworkManager-l2tp (affected versions not specified)
Description Improper input validation allows local users with VPN connection creation permissions to inject arbitrary pppd directives. By providing mru or mtu property values that contain non-numeric content following a valid integer, an attacker can exploit the write config option() function, which writes unvalidated strings directly into the pppd options file. This allows the injection of a plugin directive, leading the privileged pppd process to load a malicious shared object and execute arbitrary code with root privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15031
CVE-2026-93337
GHSA-RP84-8H2R-5XC3

Affected Products

Networkmanager-L2Tp