Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-91839
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-91839 is a local privilege escalation vulnerability in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager, caused by improper handling of CR/LF characters in VPN connection profile credentials. A local unprivileged user can craft a malicious VPN profile to inject additional configuration directives, leading to arbitrary code execution with root privileges when the VPN connection is activated. The CVE was reported on September 15, 2026, by researcher Andreas Gabriel Berbescu and is currently in "Reserved" status. It carries a HIGH severity estimate with CWE-93 (Improper Neutralization of CRLF Sequences) classification (Red Hat CVE, Red Hat Bugzilla).

Technical details

The root cause is CWE-93 (Improper Neutralization of CRLF Sequences / CRLF Injection) in the nm-fortisslvpn-service component, which fails to sanitize carriage-return (\r) and line-feed (\n) characters present in VPN connection profile credentials. An attacker can embed these characters within credential fields of a crafted VPN profile, causing the service to interpret injected content as additional configuration directives when the profile is parsed. Because the service runs with elevated (root) privileges, the injected directives execute in that privileged context. Exploitation requires local, unprivileged access to the target system and the ability to create or modify a VPN connection profile (Red Hat CVE, Red Hat Bugzilla).

Impact

Successful exploitation allows a local unprivileged user to escalate privileges to root on the affected system, resulting in complete compromise of confidentiality, integrity, and availability. An attacker with root access can read or exfiltrate sensitive data, install persistent backdoors, modify system configurations, and potentially pivot to other systems on the network. The attack is triggered at VPN connection activation, which may occur automatically or be induced by the attacker (Red Hat CVE).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the time of disclosure. The CVE status remains "Reserved" and no EPSS score or CISA KEV catalog entry has been identified. Exploitation requires local access to the system, limiting the attack surface compared to remote vulnerabilities, but the privilege escalation to root makes it a high-value target for post-compromise scenarios (Red Hat CVE, Red Hat Bugzilla).

Exploitation steps

  1. Gain local access: Obtain an unprivileged local user account on a system with the NetworkManager-fortisslvpn plugin installed.
  2. Craft a malicious VPN profile: Create a VPN connection profile (e.g., via NetworkManager's configuration files or GUI) and embed CR/LF sequences (\r\n) within credential fields such as the username or password to inject additional configuration directives.
  3. Inject configuration directives: The injected content after the CRLF sequence is interpreted by nm-fortisslvpn-service as a new configuration line, allowing the attacker to specify arbitrary directives (e.g., commands to execute, scripts to run).
  4. Activate the VPN connection: Trigger activation of the crafted VPN connection profile, either directly or by waiting for an automated reconnect event.
  5. Achieve root code execution: The nm-fortisslvpn-service, running as root, processes the injected directives and executes the attacker-controlled commands with root privileges, completing the privilege escalation (Red Hat CVE, Red Hat Bugzilla).

Indicators of compromise

  • File System: Unexpected or newly created VPN connection profile files in /etc/NetworkManager/system-connections/ or ~/.local/share/networkmanager/ containing CR/LF sequences (\r\n) in credential fields.
  • Logs: Entries in /var/log/messages or journalctl showing nm-fortisslvpn-service spawning unexpected child processes or executing unusual commands at VPN connection activation time.
  • Process: Unusual processes (e.g., reverse shells, bash, python, curl, wget) spawned as children of nm-fortisslvpn-service or with root privileges shortly after a VPN connection event.
  • Network: Unexpected outbound network connections from the host to unknown IP addresses following VPN profile activation.

Mitigation and workarounds

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product, though this assessment may evolve. As a workaround, if the NetworkManager-fortisslvpn plugin is not required, it should be removed to eliminate the attack surface using sudo dnf remove NetworkManager-fortisslvpn; a system restart may be required. Organizations relying on FortiSSLVPN connectivity should monitor for an upstream patch and apply it promptly upon release, and in the interim restrict local user access to VPN profile creation and modification (Red Hat CVE).

Community reactions

Red Hat acknowledged the vulnerability and credited researcher Andreas Gabriel Berbescu for the report. Red Hat Product Security assessed that no currently supported Red Hat product is affected, though they noted the assessment may evolve. No significant broader community or media reactions have been identified at this time (Red Hat CVE, Red Hat Bugzilla).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Affected

bookworm

network-manager-fortisslvpn

Affected

Ubuntu

Unknown

bionic (esm-apps)

network-manager-fortisslvpn

Unknown

focal (esm-apps)

network-manager-fortisslvpn

Unknown

jammy

network-manager-fortisslvpn

Unknown

jammy (esm-apps)

network-manager-fortisslvpn

Unknown

noble

network-manager-fortisslvpn

Unknown

noble (esm-apps)

network-manager-fortisslvpn

Unknown

SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93574MEDIUM6.5
  • Linux Debian logoLinux Debian
  • netty
NoNoSep 18, 2026
CVE-2026-93562MEDIUM6.5
  • Linux Debian logoLinux Debian
  • netty
NoNoSep 18, 2026
CVE-2026-93894LOW2.3
  • Linux Debian logoLinux Debian
  • varnish
NoNoSep 18, 2026
CVE-2026-82560NONEN/A
  • Linux Debian logoLinux Debian
  • perl
NoNoSep 19, 2026
CVE-2026-78030NONEN/A
  • Linux Debian logoLinux Debian
  • perl-DBI
NoYesSep 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management