Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-91841
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-91841 is a CRLF injection vulnerability in NetworkManager-vpnc, a VPN plugin for NetworkManager, that allows a local unprivileged user to escalate privileges to root. The flaw is described as an incomplete fix for the earlier CVE-2018-10900, exploitable by injecting a newline character into the CA-File path to execute arbitrary commands as root. The CVE was published on September 15, 2026, and is currently in "Reserved" status. Red Hat Product Security has determined that no currently supported Red Hat product is affected. A CVSS score has not been publicly disclosed at this time (Red Hat CVE, Red Hat Bugzilla).

Technical details

The vulnerability is classified as CWE-93 (Improper Neutralization of CRLF Sequences / CRLF Injection). An attacker with local, unprivileged access can inject a newline character (\n) into the CA-File path field used by the NetworkManager-vpnc plugin. Because the plugin processes this path without adequately sanitizing newline characters, the injected content is interpreted as additional configuration directives, ultimately allowing arbitrary command execution in the context of the root user. This is explicitly noted as an incomplete remediation of CVE-2018-10900, which addressed a similar newline injection issue in the same component (Red Hat CVE).

Impact

Successful exploitation grants a local unprivileged attacker the ability to execute arbitrary commands as root, resulting in full local privilege escalation. This compromises the integrity and confidentiality of the affected system, as the attacker gains complete control over the host. The technical impact is classified as "Modify Application Data" under CWE-93, but in practice the root-level command execution extends well beyond data modification to full system compromise (Red Hat CVE).

Exploitability

No public proof-of-concept exploit code, active in-the-wild exploitation, or threat actor attribution has been reported for CVE-2026-91841 at this time. The CVE status remains "Reserved" and no EPSS score or CISA KEV catalog entry has been identified. Exploitation requires local access to the system, limiting the attack surface compared to remotely exploitable vulnerabilities (Red Hat CVE).

Exploitation steps

  1. Gain local access: Obtain a local unprivileged shell on a system with the NetworkManager-vpnc plugin installed.
  2. Identify the CA-File path field: Locate the NetworkManager VPN connection configuration that accepts a CA-File path, accessible via the NetworkManager settings or configuration files.
  3. Inject newline character: Set the CA-File path value to include a newline character (\n) followed by a malicious vpnc configuration directive (e.g., a script or command to be executed as root).
  4. Trigger VPN connection: Initiate or cause the VPN connection to be established, prompting NetworkManager-vpnc to process the manipulated CA-File path.
  5. Achieve root command execution: The injected newline causes the vpnc plugin to interpret the appended content as an additional configuration directive, executing the attacker-supplied command with root privileges (Red Hat CVE).

Indicators of compromise

  • Logs: Unexpected or anomalous entries in /var/log/messages or journalctl output related to NetworkManager-vpnc VPN connection events, particularly those involving unusual CA-File paths containing newline or special characters.
  • File System: Unexpected files created in privileged directories (e.g., /root/, /etc/) by non-root users; new cron jobs, SUID binaries, or SSH authorized keys added to the root account.
  • Process: Unusual processes spawned as root (e.g., shells, reverse connections) with a parent process traceable to NetworkManager or vpnc.
  • Network: Unexpected outbound connections from the host following VPN connection events, potentially indicating post-exploitation activity (Red Hat CVE).

Mitigation and workarounds

Red Hat Product Security has determined that no currently supported Red Hat product is affected by this vulnerability. As a workaround, Red Hat recommends removing the NetworkManager-vpnc package if vpnc-based VPN functionality is not required, using the command sudo dnf remove NetworkManager-vpnc. This will disable vpnc VPN connections but eliminates the attack surface. Users of affected upstream versions of NetworkManager-vpnc should monitor the upstream project for a patched release (Red Hat CVE).

Community reactions

Red Hat Product Security acknowledged the vulnerability and credited Andreas Gabriel Berbescu for reporting the issue. Red Hat explicitly noted that this CVE represents an incomplete fix for the previously disclosed CVE-2018-10900, highlighting a recurring weakness in the same component. No significant broader media coverage or notable researcher commentary beyond the Red Hat advisory has been identified at this time (Red Hat CVE).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Affected

bookworm

network-manager-vpnc

Affected

sid

network-manager-vpnc

Affected

trixie

network-manager-vpnc

Affected

Ubuntu

Unknown

bionic (esm-apps)

network-manager-vpnc

Unknown

devel

network-manager-vpnc

Unknown

focal (esm-apps)

network-manager-vpnc

Unknown

jammy

network-manager-vpnc

Unknown

jammy (esm-apps)

network-manager-vpnc

Unknown

noble

network-manager-vpnc

Unknown

noble (esm-apps)

network-manager-vpnc

Unknown

resolute

network-manager-vpnc

Unknown

SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61721HIGH8
  • Linux Debian logoLinux Debian
  • fluidsynth
NoYesSep 18, 2026
CVE-2026-61714HIGH7.8
  • Linux Debian logoLinux Debian
  • fluidsynth
NoYesSep 18, 2026
CVE-2026-61723MEDIUM6.8
  • Linux Debian logoLinux Debian
  • fluidsynth
NoYesSep 18, 2026
CVE-2026-61722MEDIUM6.8
  • Linux Debian logoLinux Debian
  • fluidsynth
NoYesSep 18, 2026
CVE-2026-61720MEDIUM6.2
  • Linux Debian logoLinux Debian
  • fluidsynth
NoYesSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management