PT-2026-98959 · Networkmanager · Networkmanager-Ssh
CVE-2026-91838
·
Published
2026-09-17
·
Updated
2026-09-25
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NetworkManager-sstp (affected versions not specified)
Description
A flaw in the SSTP VPN plugin for NetworkManager allows a local unprivileged user to execute arbitrary commands with root privileges. The issue occurs when shell metacharacters—special characters that can be interpreted as commands by a shell—are embedded into VPN connection profile fields, such as the CA certificate or proxy settings. These characters are processed without proper escaping by the
pppd daemon, which operates with elevated permissions, leading to command execution when a malicious VPN connection is activated.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Networkmanager-Ssh