CVE-2026-91840

NameCVE-2026-91840
DescriptionA flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration to execute an arbitrary program with root privileges when the malicious VPN connection is activated.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1148113

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
network-manager-vpnc (PTS)bookworm1.2.8-4vulnerable
trixie1.4.0-2vulnerable
forky, sid1.4.0-4vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
network-manager-vpncsource(unstable)(unfixed)1148113

Notes

https://gitlab.gnome.org/Archive/NetworkManager-vpnc/-/work_items/19
https://blogs.gnome.org/mcatanzaro/2026/09/15/privilege-escalation-vulnerabilities-in-networkmanager-plugins/

Search for package or bug name: Reporting problems