Local User Exploit in NetworkManager's WPA-Enterprise Configuration
CVE-2026-19685

9.8CRITICAL

What is CVE-2026-19685?

A flaw in NetworkManager permits an unprivileged local user to bypass server certificate validation by manipulating directory-valued connection properties of a private WPA-Enterprise (802.1X) connection profile. This occurs due to the failure to enforce a proper user restriction on specific settings, enabling attackers to redirect CA paths to their own controlled directories. Consequently, this vulnerability poses significant risks for credential theft and man-in-the-middle attacks via rogue access points, undermining the security of the network.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Vivek Parikh (BreachX Zero Day Labs) for reporting this issue.
.