CVE-2026-91841: Gnome Networkmanager-Vpnc
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by injecting a newline character into the CA-File path. This manipulation allows the user to execute arbitrary commands as the root user, leading to local privilege escalation.
Affected products
- Gnome Networkmanager-Vpnc: any version
Published 2026-09-25. Last modified 2026-09-30.