CVE-2026-91841: Gnome Networkmanager-Vpnc

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by injecting a newline character into the CA-File path. This manipulation allows the user to execute arbitrary commands as the root user, leading to local privilege escalation.

Affected products

  • Gnome Networkmanager-Vpnc: any version

Published 2026-09-25. Last modified 2026-09-30.