
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-91841 is a CRLF injection vulnerability in NetworkManager-vpnc, a VPN plugin for NetworkManager, that allows a local unprivileged user to escalate privileges to root. The flaw is described as an incomplete fix for the earlier CVE-2018-10900, exploitable by injecting a newline character into the CA-File path to execute arbitrary commands as root. The CVE was published on September 15, 2026, and is currently in "Reserved" status. Red Hat Product Security has determined that no currently supported Red Hat product is affected. A CVSS score has not been publicly disclosed at this time (Red Hat CVE, Red Hat Bugzilla).
The vulnerability is classified as CWE-93 (Improper Neutralization of CRLF Sequences / CRLF Injection). An attacker with local, unprivileged access can inject a newline character (\n) into the CA-File path field used by the NetworkManager-vpnc plugin. Because the plugin processes this path without adequately sanitizing newline characters, the injected content is interpreted as additional configuration directives, ultimately allowing arbitrary command execution in the context of the root user. This is explicitly noted as an incomplete remediation of CVE-2018-10900, which addressed a similar newline injection issue in the same component (Red Hat CVE).
Successful exploitation grants a local unprivileged attacker the ability to execute arbitrary commands as root, resulting in full local privilege escalation. This compromises the integrity and confidentiality of the affected system, as the attacker gains complete control over the host. The technical impact is classified as "Modify Application Data" under CWE-93, but in practice the root-level command execution extends well beyond data modification to full system compromise (Red Hat CVE).
No public proof-of-concept exploit code, active in-the-wild exploitation, or threat actor attribution has been reported for CVE-2026-91841 at this time. The CVE status remains "Reserved" and no EPSS score or CISA KEV catalog entry has been identified. Exploitation requires local access to the system, limiting the attack surface compared to remotely exploitable vulnerabilities (Red Hat CVE).
NetworkManager-vpnc plugin installed.\n) followed by a malicious vpnc configuration directive (e.g., a script or command to be executed as root)./var/log/messages or journalctl output related to NetworkManager-vpnc VPN connection events, particularly those involving unusual CA-File paths containing newline or special characters./root/, /etc/) by non-root users; new cron jobs, SUID binaries, or SSH authorized keys added to the root account.Red Hat Product Security has determined that no currently supported Red Hat product is affected by this vulnerability. As a workaround, Red Hat recommends removing the NetworkManager-vpnc package if vpnc-based VPN functionality is not required, using the command sudo dnf remove NetworkManager-vpnc. This will disable vpnc VPN connections but eliminates the attack surface. Users of affected upstream versions of NetworkManager-vpnc should monitor the upstream project for a patched release (Red Hat CVE).
Red Hat Product Security acknowledged the vulnerability and credited Andreas Gabriel Berbescu for reporting the issue. Red Hat explicitly noted that this CVE represents an incomplete fix for the previously disclosed CVE-2018-10900, highlighting a recurring weakness in the same component. No significant broader media coverage or notable researcher commentary beyond the Red Hat advisory has been identified at this time (Red Hat CVE).
Fix availability across major Linux distributions and their releases.
bookworm
network-manager-vpnc
sid
network-manager-vpnc
trixie
network-manager-vpnc
bionic (esm-apps)
network-manager-vpnc
devel
network-manager-vpnc
focal (esm-apps)
network-manager-vpnc
jammy
network-manager-vpnc
jammy (esm-apps)
network-manager-vpnc
noble
network-manager-vpnc
noble (esm-apps)
network-manager-vpnc
resolute
network-manager-vpnc
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."