
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-91839 is a local privilege escalation vulnerability in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager, caused by improper handling of CR/LF characters in VPN connection profile credentials. A local unprivileged user can craft a malicious VPN profile to inject additional configuration directives, leading to arbitrary code execution with root privileges when the VPN connection is activated. The CVE was reported on September 15, 2026, by researcher Andreas Gabriel Berbescu and is currently in "Reserved" status. It carries a HIGH severity estimate with CWE-93 (Improper Neutralization of CRLF Sequences) classification (Red Hat CVE, Red Hat Bugzilla).
The root cause is CWE-93 (Improper Neutralization of CRLF Sequences / CRLF Injection) in the nm-fortisslvpn-service component, which fails to sanitize carriage-return (\r) and line-feed (\n) characters present in VPN connection profile credentials. An attacker can embed these characters within credential fields of a crafted VPN profile, causing the service to interpret injected content as additional configuration directives when the profile is parsed. Because the service runs with elevated (root) privileges, the injected directives execute in that privileged context. Exploitation requires local, unprivileged access to the target system and the ability to create or modify a VPN connection profile (Red Hat CVE, Red Hat Bugzilla).
Successful exploitation allows a local unprivileged user to escalate privileges to root on the affected system, resulting in complete compromise of confidentiality, integrity, and availability. An attacker with root access can read or exfiltrate sensitive data, install persistent backdoors, modify system configurations, and potentially pivot to other systems on the network. The attack is triggered at VPN connection activation, which may occur automatically or be induced by the attacker (Red Hat CVE).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the time of disclosure. The CVE status remains "Reserved" and no EPSS score or CISA KEV catalog entry has been identified. Exploitation requires local access to the system, limiting the attack surface compared to remote vulnerabilities, but the privilege escalation to root makes it a high-value target for post-compromise scenarios (Red Hat CVE, Red Hat Bugzilla).
NetworkManager-fortisslvpn plugin installed.\r\n) within credential fields such as the username or password to inject additional configuration directives.nm-fortisslvpn-service as a new configuration line, allowing the attacker to specify arbitrary directives (e.g., commands to execute, scripts to run).nm-fortisslvpn-service, running as root, processes the injected directives and executes the attacker-controlled commands with root privileges, completing the privilege escalation (Red Hat CVE, Red Hat Bugzilla)./etc/NetworkManager/system-connections/ or ~/.local/share/networkmanager/ containing CR/LF sequences (\r\n) in credential fields./var/log/messages or journalctl showing nm-fortisslvpn-service spawning unexpected child processes or executing unusual commands at VPN connection activation time.bash, python, curl, wget) spawned as children of nm-fortisslvpn-service or with root privileges shortly after a VPN connection event.Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product, though this assessment may evolve. As a workaround, if the NetworkManager-fortisslvpn plugin is not required, it should be removed to eliminate the attack surface using sudo dnf remove NetworkManager-fortisslvpn; a system restart may be required. Organizations relying on FortiSSLVPN connectivity should monitor for an upstream patch and apply it promptly upon release, and in the interim restrict local user access to VPN profile creation and modification (Red Hat CVE).
Red Hat acknowledged the vulnerability and credited researcher Andreas Gabriel Berbescu for the report. Red Hat Product Security assessed that no currently supported Red Hat product is affected, though they noted the assessment may evolve. No significant broader community or media reactions have been identified at this time (Red Hat CVE, Red Hat Bugzilla).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."