Local Privilege Escalation Vulnerability in NetworkManager-fortisslvpn by Fortinet
CVE-2026-91839
7.8HIGH
What is CVE-2026-91839?
A vulnerability has been identified in the FortiSSLVPN plugin for NetworkManager where improper handling of carriage-return/line-feed (CR/LF) characters may allow an unprivileged local user to craft a malicious VPN profile. Exploiting this flaw can result in the injection of arbitrary configuration directives, potentially leading to arbitrary code execution with root privileges once the malicious VPN connection is activated.
Affected Version(s)
NetworkManager-fortisslvpn 0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Andreas Gabriel Berbescu for reporting this issue.