A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields such as CA certificate or proxy settings. These unescaped characters are then processed by the `pppd` daemon, which runs with root privileges, allowing the attacker to execute arbitrary commands with elevated permissions when a malicious VPN connection is activated.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

The vulnerability requires a local unprivileged user to activate a malicious VPN connection. If the NetworkManager-sstp package is not required, removing it will eliminate the attack vector. To remove the `NetworkManager-sstp` package: `sudo dnf remove NetworkManager-sstp` This action may impact functionality that relies on SSTP VPN connections.

History

Fri, 25 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 25 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields such as CA certificate or proxy settings. These unescaped characters are then processed by the `pppd` daemon, which runs with root privileges, allowing the attacker to execute arbitrary commands with elevated permissions when a malicious VPN connection is activated.
Title Networkmanager-sstp: networkmanager-sstp: local privilege escalation to root via shell injection in vpn profile fields
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2026-09-25T18:16:17.928Z

Reserved: 2026-09-15T08:28:01.333Z

Link: CVE-2026-91838

cve-icon Vulnrichment

Updated: 2026-09-25T18:16:13.869Z

cve-icon NVD

Status : Received

Published: 2026-09-25T18:17:32.530

Modified: 2026-09-25T19:17:58.647

Link: CVE-2026-91838

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T20:30:17Z

Weaknesses