CVE-2026-19685
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-19685 is an incorrect authorization vulnerability in NetworkManager that allows an unprivileged local user to bypass WPA-Enterprise (802.1X) server certificate validation by pointing a private connection profile's CA path at an attacker-controlled directory. It is an incomplete fix for CVE-2025-9615, which hardened FILE-typed certificate and key properties but omitted the directory-valued 802-1x.ca-path and phase2-ca-path properties from the private_user restriction. The vulnerability was reported by Vivek Parikh of BreachX Zero Day Labs via CERT-In coordinated disclosure and publicly disclosed on August 24, 2026. It carries a CVSS v3.1 base score of 7.1 (High) per Red Hat's authoritative scoring (Red Hat CVE, Red Hat Bugzilla).

Technical details

The root cause is CWE-863 (Incorrect Authorization): when CVE-2025-9615 was patched, the private_user ownership guard was applied to FILE-typed certificate/key properties and pac-file, but the directory-valued 802-1x.ca-path and phase2-ca-path properties were not included. NetworkManager (running as root) passes these directory paths to wpa_supplicant without verifying ownership, allowing an unprivileged local user with the settings.modify.own polkit permission — typically granted passwordlessly on desktop systems — to set these properties on a private connection profile to an attacker-controlled CA directory. Exploitation requires an active local user session; it is not reachable from a remote or inactive SSH session. The reporter's proof-of-concept demonstrated capture of MSCHAPv2 hashes via hostapd-wpe on an evil-twin access point (Red Hat CVE, Red Hat Bugzilla).

Impact

A successful exploit allows an unprivileged local user to subvert WPA-Enterprise (802.1X) server certificate validation on private connection profiles (e.g., corporate or eduroam Wi-Fi), enabling an evil-twin access point to pass certificate validation and capture EAP credentials such as MSCHAPv2 hashes. The impact is limited to WPA-Enterprise connections; open and WPA2-Personal (PSK) networks are unaffected. Captured credentials could enable lateral movement into enterprise networks, session hijacking, or further credential-based attacks (Red Hat CVE, Red Hat Bugzilla).

Exploitability

No public proof-of-concept exploit code has been released, though the reporter demonstrated a working PoC using hostapd-wpe to capture MSCHAPv2 hashes in a coordinated disclosure. There is no evidence of in-the-wild exploitation at this time, and the CVE is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is 0.0, reflecting low current exploitation probability. NVD's SSVC assessment notes the vulnerability is automatable, though Red Hat disputes the CISA-assigned CVSS 9.8 AV:N score as incorrect for this local-access issue (Red Hat CVE, Red Hat Bugzilla).

Exploitation steps

  1. Gain local access: Obtain an unprivileged local user session on a Linux system running a vulnerable version of NetworkManager (1.57.1-dev through 1.58.0) with the settings.modify.own polkit permission (typically granted passwordlessly on desktop systems).
  2. Prepare attacker-controlled CA directory: Create a directory containing a rogue CA certificate that the attacker controls, which will be used to sign certificates for a rogue access point.
  3. Modify private connection profile: Using nmcli or the NetworkManager D-Bus API, set the 802-1x.ca-path or phase2-ca-path property of an existing private WPA-Enterprise (802.1X) connection profile (e.g., a corporate or eduroam profile) to point to the attacker-controlled CA directory.
  4. Deploy rogue access point: Set up an evil-twin access point (e.g., using hostapd-wpe) with a certificate signed by the attacker's rogue CA, mimicking the legitimate enterprise network SSID.
  5. Capture EAP credentials: When the victim's device connects to the rogue AP (which now passes certificate validation due to the manipulated CA path), capture EAP credentials such as MSCHAPv2 challenge/response hashes for offline cracking or relay attacks (Red Hat Bugzilla, Red Hat CVE).

Indicators of compromise

  • Logs: NetworkManager logs (/var/log/NetworkManager or journalctl -u NetworkManager) showing changes to 802-1x.ca-path or phase2-ca-path properties on private connection profiles to non-standard directories; wpa_supplicant logs referencing unexpected CA path directories.
  • File System: Presence of unexpected CA certificate directories in user-writable locations (e.g., /tmp/, /home/<user>/, or other non-system paths) referenced in NetworkManager connection profiles stored under /etc/NetworkManager/system-connections/ or ~/.local/share/NetworkManager/.
  • Network: Wireless association events to access points with SSIDs matching known enterprise networks but with unexpected BSSID or signal characteristics; EAP authentication failures or unexpected authentication method negotiations in wpa_supplicant logs.
  • Process: Unexpected invocations of nmcli connection modify or D-Bus calls to org.freedesktop.NetworkManager modifying 802.1X properties by non-administrative users (Red Hat CVE, Red Hat Bugzilla).

Mitigation and workarounds

The upstream fix is available in NetworkManager 1.58.1 (and later 1.60 development snapshots), implemented in commit a8e87381 via merge request MR 2513, which causes NetworkManager to reject 802-1x.ca-path and 802-1x.phase2-ca-path on private connections and require ca-cert or system-ca-certs instead. Until the patched package is installed, administrators should use system-wide 802.1X profiles rather than per-user private ones, or set 802-1x.system-ca-certs=yes so the compiled system CA path overrides any user-supplied ca-path. Restricting local user access to NetworkManager connection profile configurations and monitoring for suspicious certificate validation failures in wireless logs are additional interim measures (Red Hat CVE, Red Hat Bugzilla).

Community reactions

Red Hat explicitly noted that CISA's assigned CVSS score of 9.8 with AV:N is incorrect for this vulnerability, which requires a local active session, and set nist_cvss_validation to REJECTED in their Bugzilla tracking. The vulnerability was reported through CERT-In coordinated disclosure by Vivek Parikh of BreachX Zero Day Labs (BreachPoint Pvt Ltd, India), with notifications also sent to Ubuntu Security and Debian Security teams. Community discussion was observed on Mastodon via accounts such as @RedPacketSecurity and @cR0w, reflecting routine security community awareness rather than significant alarm (Red Hat Bugzilla, Red Hat CVE).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78683CRITICAL9.4
  • Linux Debian logoLinux Debian
  • nltk
NoYesAug 25, 2026
CVE-2026-78682HIGH8.7
  • Linux Debian logoLinux Debian
  • nltk
NoYesAug 25, 2026
CVE-2026-78681HIGH8.7
  • Linux Debian logoLinux Debian
  • nltk
NoYesAug 25, 2026
CVE-2026-78680HIGH8.5
  • Linux Debian logoLinux Debian
  • nltk
NoYesAug 25, 2026
CVE-2026-78679HIGH7.1
  • Linux Debian logoLinux Debian
  • python-git
NoNoAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management