Description
A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged user can create and activate their own L2TP VPN profile containing a newline-injected leftupdown directive; pluto executes that command as root when the IKE security association is established, resulting in local privilege escalation. This is the same bug class as CVE-2018-10900 (NetworkManager-vpnc).
Published: 2026-09-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

A local unprivileged user can create a custom L2TP VPN profile that injects a newline into the leftupdown directive. NetworkManager‑l2tp writes the unescaped VPN configuration into ipsec.conf, which pluto loads as root during IKE association establishment. The injected command is then executed with root privileges, giving the attacker local privilege escalation. This flaw is an instance of CWE-88, where untrusted data is passed to a parser that can change the program's behavior.

Affected Systems

The vulnerability affects the NetworkManager‑l2tp plugin used by Fedora and Fedora’s Extra Packages for. All versions of the plugin prior to the latest update that includes the input‑escaping fix are potentially vulnerable. No specific product versions are listed in the advisory, so any release that contains an unpatched NetworkManager‑l2tp package must be considered at risk.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity, while the EPSS score is < 1%; the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to have local unprivileged access and the ability to create or edit VPN profiles, a capability normally available to regular users. The attack vector is local, with the attacker crafting a malicious ipsec.conf entry that is processed by pluto with root privileges. The availability of the fix in the current Fedora update stream reduces the window for exploitation when the patch is applied.

Generated by OpenCVE AI on September 20, 2026 at 22:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest NetworkManager‑l2tp update from the Fedora EPEL or Fedora repository, which removes the newline injection vulnerability.
  • Delete any user‑created L2TP VPN profiles that may contain malicious directives until the patch is applied.
  • Temporarily disable or uninstall the NetworkManager‑l2tp plugin if the patch cannot be applied immediately, preventing the vulnerable code from executing.
  • Ensure SELinux or equivalent access controls are enforced to limit root process exposure.

Generated by OpenCVE AI on September 20, 2026 at 22:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4808-1 network-manager-l2tp security update
Debian DSA Debian DSA DSA-6498-1 network-manager-l2tp security update
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged user can create and activate their own L2TP VPN profile containing a newline-injected leftupdown directive; pluto executes that command as root when the IKE security association is established, resulting in local privilege escalation. This is the same bug class as CVE-2018-10900 (NetworkManager-vpnc).
Title NetworkManager-l2tp: local privilege escalation via ipsec.conf injection
Weaknesses CWE-88
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2026-09-14T19:43:32.531Z

Reserved: 2026-08-12T14:50:47.790Z

Link: CVE-2026-19624

cve-icon Vulnrichment

Updated: 2026-09-14T19:43:28.438Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T20:16:43.593

Modified: 2026-09-18T19:34:36.657

Link: CVE-2026-19624

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:45:05Z

Weaknesses
  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')