{"id":"CVE-2026-19624","summary":"NetworkManager-l2tp: local privilege escalation via ipsec.conf injection","details":"A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged user can create and activate their own L2TP VPN profile containing a newline-injected leftupdown directive; pluto executes that command as root when the IKE security association is established, resulting in local privilege escalation. This is the same bug class as CVE-2018-10900 (NetworkManager-vpnc).","modified":"2026-09-16T08:11:33.737214Z","published":"2026-09-14T19:19:43.736Z","database_specific":{"cna_assigner":"fedora","cwe_ids":["CWE-88"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19624.json"},"references":[{"type":"ADVISORY","url":"https://bodhi.fedoraproject.org/updates/?packages=NetworkManager-l2tp"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19624.json"},{"type":"ADVISORY","url":"https://github.com/nm-l2tp/NetworkManager-l2tp/releases"},{"type":"ADVISORY","url":"https://linnemanlabs.com/posts/nm-l2tp-newline-to-root/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19624"},{"type":"FIX","url":"https://github.com/nm-l2tp/NetworkManager-l2tp/commit/3704d8c9d5e5f9ed1626a8ce7627a04247cea673"},{"type":"FIX","url":"https://github.com/nm-l2tp/NetworkManager-l2tp/commit/95b6b46f48a0c9eabc79272cd313f219110ef91c"},{"type":"PACKAGE","url":"https://github.com/nm-l2tp/NetworkManager-l2tp"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nm-l2tp/networkmanager-l2tp","events":[{"introduced":"75a61b1a02161bb10dc0f61cc23318368c8f8318"},{"introduced":"0"},{"introduced":"d357d871285b0769a8f668f89d4e510f637e030b"},{"introduced":"c13cea994d5830cf2ce683a89987f58eb4a7f0f7"},{"introduced":"9e35c9a9af5c5d2e1d88efd91aa30c7a9176a24c"},{"fixed":"837b58ea5dc5c6aef8a9c57e948e6853c89f6159"},{"fixed":"36963888b168873425dae3aa57deaea84451a588"},{"fixed":"75806b1359fb8946acba24f7cdcf3f26f1b40b40"},{"fixed":"854179811e2a83206b7301bd2ea658bdb284c72b"},{"fixed":"ef970e2f3bf3e219d99c949b7a91a6bb55ab6ef7"},{"fixed":"3704d8c9d5e5f9ed1626a8ce7627a04247cea673"},{"fixed":"95b6b46f48a0c9eabc79272cd313f219110ef91c"}],"database_specific":{"extracted_events":[{"introduced":"1.0.0"},{"fixed":"1.0.16"},{"introduced":"1.2.0"},{"fixed":"1.2.22"},{"introduced":"1.8.0"},{"fixed":"1.8.10"},{"introduced":"1.20.0"},{"fixed":"1.20.24"},{"introduced":"1.52.0"},{"fixed":"1.52.4"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["1.20.22","1.8.8","1.2.20","1.0.14","1.52.2","1.52.0","1.20.20","1.20.18","1.20.16","1.20.14","1.20.12","1.20.10","1.20.8","1.20.6","1.20.4","1.8.6","1.2.18","1.0.12","1.20.2","1.20.0","1.8.4","1.8.2","1.2.16","1.8.0","1.2.14","1.2.12","1.0.10","1.0.8","1.2.10","1.2.8","1.0.6","1.2.6","1.2.4","1.0.4","1.0.2","1.0.0","0.9.8.7","0.9.8.6","0.9.8.5","0.9.8.4","0.9.8","0.9.6","0.9.4","0.3.3","0.3.2","0.3.1","0.3.0","0.2","0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19624.json","vanir_signatures_modified":"2026-09-16T08:11:33Z","vanir_signatures":[{"deprecated":false,"digest":{"length":1924,"function_hash":"13964438800715637485908274376023140312"},"id":"CVE-2026-19624-1d69c2a3","signature_type":"Function","signature_version":"v1","source":"https://github.com/nm-l2tp/networkmanager-l2tp/commit/95b6b46f48a0c9eabc79272cd313f219110ef91c","target":{"file":"src/nm-l2tp-service.c","function":"handle_need_secrets"}},{"target":{"function":"validate_one_property","file":"src/nm-l2tp-service.c"},"deprecated":false,"digest":{"function_hash":"17669389332226560085624569025636570449","length":1578},"id":"CVE-2026-19624-54fce860","signature_type":"Function","signature_version":"v1","source":"https://github.com/nm-l2tp/networkmanager-l2tp/commit/95b6b46f48a0c9eabc79272cd313f219110ef91c"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/nm-l2tp/networkmanager-l2tp/commit/95b6b46f48a0c9eabc79272cd313f219110ef91c","target":{"file":"src/nm-l2tp-service.c"},"deprecated":false,"digest":{"line_hashes":["56729098099101703669903456529156069862","259250658643546897148582399276164297545","65111469976273515679866129474813356740","255306186292428187255093885943112397075","45908978728976663032842464259496126954","23822332537171051940890045257615178007","74716615936422012258224446761907090011","258992435164776269446931223689317742243","122006297347136451589395573509347081141","129312901362782005781301822372212109375","279540930461600882574606516120782951896","276414130930462079905725293414921215373","34589620706289540010224129368596713432","198936859782390531681175885044565144982","243052109151728983703982316010310873881","213061877386431798874054128151116495358","299278647089658727051815064060003491750"],"threshold":0.9},"id":"CVE-2026-19624-9113a730"},{"deprecated":false,"digest":{"function_hash":"69003167894437558481569827080944388652","length":20801},"id":"CVE-2026-19624-bf0efa55","signature_type":"Function","signature_version":"v1","source":"https://github.com/nm-l2tp/networkmanager-l2tp/commit/95b6b46f48a0c9eabc79272cd313f219110ef91c","target":{"file":"src/nm-l2tp-service.c","function":"nm_l2tp_config_write"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}