{"api_version":"1","generated_at":"2026-09-27T07:16:58+00:00","cve":"CVE-2026-91838","urls":{"html":"https://cve.report/CVE-2026-91838","api":"https://cve.report/api/cve/CVE-2026-91838.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-91838","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-91838"},"summary":{"title":"Networkmanager-sstp: networkmanager-sstp: local privilege escalation to root via shell injection in vpn profile fields","description":"A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields such as CA certificate or proxy settings. These unescaped characters are then processed by the `pppd` daemon, which runs with root privileges, allowing the attacker to execute arbitrary commands with elevated permissions when a malicious VPN connection is activated.","state":"PUBLISHED","assigner":"fedora","published_at":"2026-09-25 18:17:32","updated_at":"2026-09-25 19:17:58"},"problem_types":["CWE-78","CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"],"metrics":[{"version":"3.1","source":"patrick@puiterwijk.org","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://gitlab.gnome.org/GNOME/network-manager-sstp/-/work_items/67","name":"https://gitlab.gnome.org/GNOME/network-manager-sstp/-/work_items/67","refsource":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/security/cve/CVE-2026-91838","name":"https://access.redhat.com/security/cve/CVE-2026-91838","refsource":"patrick@puiterwijk.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533637","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2533637","refsource":"patrick@puiterwijk.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-91838","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91838","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"GNOME","product":"NetworkManager-sstp","version":"affected * semver","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-09-15T09:39:06.004Z","lang":"en","value":"Reported to Red Hat."},{"source":"CNA","time":"2026-09-15T09:39:06.004Z","lang":"en","value":"Made public."}],"solutions":[],"workarounds":[{"source":"CNA","title":"","value":"The vulnerability requires a local unprivileged user to activate a malicious VPN connection. If the NetworkManager-sstp package is not required, removing it will eliminate the attack vector.\n\nTo remove the `NetworkManager-sstp` package:\n`sudo dnf remove NetworkManager-sstp`\n\nThis action may impact functionality that relies on SSTP VPN connections.","time":"","lang":"en"}],"exploits":[],"credits":[{"source":"CNA","value":"Red Hat would like to thank Andreas Gabriel Berbescu for reporting this issue.","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"91838","cve":"CVE-2026-91838","epss":"0.001000000","percentile":"0.008170000","score_date":"2026-09-26","updated_at":"2026-09-27 00:04:19"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-91838","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-09-25T18:16:05.405073Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-25T18:16:17.928Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"references":[{"tags":["exploit"],"url":"https://gitlab.gnome.org/GNOME/network-manager-sstp/-/work_items/67"}],"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"collectionURL":"https://gitlab.gnome.org/GNOME/network-manager-sstp","defaultStatus":"unaffected","packageName":"network-manager-sstp","product":"NetworkManager-sstp","vendor":"GNOME","versions":[{"lessThan":"*","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","value":"Red Hat would like to thank Andreas Gabriel Berbescu for reporting this issue."}],"datePublic":"2026-09-15T09:39:06.004Z","descriptions":[{"lang":"en","value":"A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields such as CA certificate or proxy settings. These unescaped characters are then processed by the `pppd` daemon, which runs with root privileges, allowing the attacker to execute arbitrary commands with elevated permissions when a malicious VPN connection is activated."}],"metrics":[{"other":{"content":{"namespace":"https://access.redhat.com/security/updates/classification/","value":"Important"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-78","description":"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-25T17:51:44.357Z","orgId":"92fb86c3-55a5-4fb5-9c3f-4757b9e96dc5","shortName":"fedora"},"references":[{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2026-91838"},{"name":"RHBZ#2533637","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533637"},{"url":"https://gitlab.gnome.org/GNOME/network-manager-sstp/-/work_items/67"}],"timeline":[{"lang":"en","time":"2026-09-15T09:39:06.004Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-09-15T09:39:06.004Z","value":"Made public."}],"title":"Networkmanager-sstp: networkmanager-sstp: local privilege escalation to root via shell injection in vpn profile fields","workarounds":[{"lang":"en","value":"The vulnerability requires a local unprivileged user to activate a malicious VPN connection. If the NetworkManager-sstp package is not required, removing it will eliminate the attack vector.\n\nTo remove the `NetworkManager-sstp` package:\n`sudo dnf remove NetworkManager-sstp`\n\nThis action may impact functionality that relies on SSTP VPN connections."}],"x_generator":{"engine":"cvelib 1.8.0"},"x_redhatCweChain":"CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}},"cveMetadata":{"assignerOrgId":"92fb86c3-55a5-4fb5-9c3f-4757b9e96dc5","assignerShortName":"fedora","cveId":"CVE-2026-91838","datePublished":"2026-09-25T17:51:44.357Z","dateReserved":"2026-09-15T08:28:01.333Z","dateUpdated":"2026-09-25T18:16:17.928Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-25 18:17:32","lastModifiedDate":"2026-09-25 19:17:58","problem_types":["CWE-78","CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"],"metrics":{"cvssMetricV31":[{"source":"patrick@puiterwijk.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-25T18:16:05.405073Z","id":"CVE-2026-91838","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"91838","Ordinal":"1","Title":"Networkmanager-sstp: networkmanager-sstp: local privilege escala","CVE":"CVE-2026-91838","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"91838","Ordinal":"1","NoteData":"A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields such as CA certificate or proxy settings. These unescaped characters are then processed by the `pppd` daemon, which runs with root privileges, allowing the attacker to execute arbitrary commands with elevated permissions when a malicious VPN connection is activated.","Type":"Description","Title":"Networkmanager-sstp: networkmanager-sstp: local privilege escala"}]}}}