Local Privilege Escalation Vulnerability in NetworkManager-fortisslvpn by Fortinet
CVE-2026-91839

7.8HIGH

Key Information:

Vendor

Gnome

Vendor
CVE Published:
25 September 2026

What is CVE-2026-91839?

A vulnerability has been identified in the FortiSSLVPN plugin for NetworkManager where improper handling of carriage-return/line-feed (CR/LF) characters may allow an unprivileged local user to craft a malicious VPN profile. Exploiting this flaw can result in the injection of arbitrary configuration directives, potentially leading to arbitrary code execution with root privileges once the malicious VPN connection is activated.

Affected Version(s)

NetworkManager-fortisslvpn 0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Andreas Gabriel Berbescu for reporting this issue.
.