PT-2026-98959 · Networkmanager · Networkmanager-Ssh

CVE-2026-91838

·

Published

2026-09-17

·

Updated

2026-09-25

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NetworkManager-sstp (affected versions not specified)
Description A flaw in the SSTP VPN plugin for NetworkManager allows a local unprivileged user to execute arbitrary commands with root privileges. The issue occurs when shell metacharacters—special characters that can be interpreted as commands by a shell—are embedded into VPN connection profile fields, such as the CA certificate or proxy settings. These characters are processed without proper escaping by the pppd daemon, which operates with elevated permissions, leading to command execution when a malicious VPN connection is activated.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91838

Affected Products

Networkmanager-Ssh