CVE-2026-91840: Gnome Networkmanager-Vpnc
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration to execute an arbitrary program with root privileges when the malicious VPN connection is activated.
Affected products
- Gnome Networkmanager-Vpnc: any version
Published 2026-09-25. Last modified 2026-09-30.