Description
NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu property values containing trailing non-numeric content after a valid integer. Attackers can exploit the verbatim write of unvalidated strings into the pppd options file via write_config_option() to inject the plugin directive, causing the privileged pppd process to load an attacker-controlled shared object and achieve arbitrary code execution as root.
Published: 2026-09-17
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation leading to arbitrary code execution as root
Action: Immediate Patch
AI Analysis

Impact

NetworkManager-l2tp is vulnerable due to improper input validation that permits local users who can create VPN connections to inject arbitrary pppd directives. By supplying mru or mtu values that contain a valid integer followed by non‑numeric characters, the application writes the unvalidated string directly into the pppd options file. This enables an attacker to add a plugin directive that loads an attacker‑controlled shared object, resulting in arbitrary code execution as root. The vulnerability is classified as CWE‑88.

Affected Systems

The affected product is NetworkManager-l2tp. Versions 1.52.4 and earlier are vulnerable. Versions 1.52.6 and later include the fix. Users should verify their installed version. If an installation relies on the default l2tp plugin, it could be affected.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity assessment. EPSS is reported as less than 1%, implying a currently low probability of exploitation in the wild, and the issue is not listed in the CISA KEV catalog. However, the attack vector remains local; an authenticated user with VPN creation privileges can launch the exploit without network access. If executed, the attacker achieves full root privileges on the host.

Generated by OpenCVE AI on September 23, 2026 at 20:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch available at the official NetworkManager-l2tp repository or upgrade to version 1.52.6 or later to address the improper input validation.
  • Restrict VPN connection creation permissions to trusted users only or remove the permission entirely if VPN setup is not required for a given system.
  • If a patch is not immediately available, disable or remove the l2tp plugin from NetworkManager and avoid using it until a fix is deployed.

Generated by OpenCVE AI on September 23, 2026 at 20:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4808-1 network-manager-l2tp security update
History

Wed, 23 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu property values containing trailing non-numeric content after a valid integer. Attackers can exploit the verbatim write of unvalidated strings into the pppd options file via write_config_option() to inject the plugin directive, causing the privileged pppd process to load an attacker-controlled shared object and achieve arbitrary code execution as root. NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu property values containing trailing non-numeric content after a valid integer. Attackers can exploit the verbatim write of unvalidated strings into the pppd options file via write_config_option() to inject the plugin directive, causing the privileged pppd process to load an attacker-controlled shared object and achieve arbitrary code execution as root.

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Nm-l2tp
Nm-l2tp networkmanager-l2tp
Vendors & Products Nm-l2tp
Nm-l2tp networkmanager-l2tp

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu property values containing trailing non-numeric content after a valid integer. Attackers can exploit the verbatim write of unvalidated strings into the pppd options file via write_config_option() to inject the plugin directive, causing the privileged pppd process to load an attacker-controlled shared object and achieve arbitrary code execution as root.
Title NetworkManager-l2tp Privilege Escalation via pppd Plugin Injection
Weaknesses CWE-88
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Nm-l2tp Networkmanager-l2tp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-23T18:07:08.359Z

Reserved: 2026-09-17T18:41:40.756Z

Link: CVE-2026-93337

cve-icon Vulnrichment

Updated: 2026-09-21T16:42:38.658Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T20:19:00.527

Modified: 2026-09-23T19:19:44.740

Link: CVE-2026-93337

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T20:45:10Z

Weaknesses
  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')