NetworkManagervpnc Privilege Escalation via Username Injection
CVE-2026-91840 Published on September 25, 2026
Networkmanager-vpnc: networkmanager-vpnc: local privilege escalation to root via newline injection in vpn username
A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration to execute an arbitrary program with root privileges when the malicious VPN connection is activated.
Vulnerability Analysis
CVE-2026-91840 is exploitable with local system access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
What is a CRLF Injection Vulnerability?
The software uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.
CVE-2026-91840 has been classified to as a CRLF Injection vulnerability or weakness.
Products Associated with CVE-2026-91840
Want to know whenever a new CVE is published for GNOME Networkmanager? stack.watch will email you.
Affected Versions
GNOME NetworkManager-vpnc:- Before * is affected.