Privilege Escalation via Unescaped Shell Metacharacters in NetworkManager-sstp
CVE-2026-91838 Published on September 25, 2026
Networkmanager-sstp: networkmanager-sstp: local privilege escalation to root via shell injection in vpn profile fields
A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields such as CA certificate or proxy settings. These unescaped characters are then processed by the `pppd` daemon, which runs with root privileges, allowing the attacker to execute arbitrary commands with elevated permissions when a malicious VPN connection is activated.
Vulnerability Analysis
CVE-2026-91838 is exploitable with local system access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
What is a Shell injection Vulnerability?
The software constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVE-2026-91838 has been classified to as a Shell injection vulnerability or weakness.
Products Associated with CVE-2026-91838
Want to know whenever a new CVE is published for GNOME Networkmanager? stack.watch will email you.
Affected Versions
GNOME NetworkManager-sstp:- Before * is affected.