CVE-2026-10805: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Red Hat Red Hat Enterprise Linux 8
A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager.
AI Analysis
Technical Summary
This vulnerability exists in NetworkManager's dhclient backend due to improper neutralization of special elements used in OS commands (OS command injection) when processing malformed MUD URLs. A local user with low privileges can escalate their privileges by exploiting this flaw, provided the system administrator has configured NetworkManager to use the dhclient backend. The default configuration uses an internal DHCP client and is not affected. Exploitation requires user interaction and has high attack complexity. The vulnerability impacts confidentiality, integrity, and availability by allowing unauthorized command execution, potentially leading to system compromise or denial of service.
Potential Impact
If exploited, an attacker with local access can execute unauthorized operating system commands with elevated privileges, potentially leading to full system compromise, data modification, or denial of service. However, exploitation requires a non-default configuration where NetworkManager is set to use dhclient, which is not enabled by default on Red Hat Enterprise Linux systems. Therefore, the risk is limited to systems with this explicit configuration change.
Mitigation Recommendations
Red Hat advises ensuring that NetworkManager is not configured to use the dhclient backend. The default configuration does not enable dhclient. If a custom configuration file such as /etc/NetworkManager/conf.d/00-dhcp.conf contains the line '[main] dhcp=dhclient', this line should be removed or commented out. After making this change, restart the NetworkManager service using 'sudo systemctl restart NetworkManager'. Note that restarting NetworkManager will temporarily disrupt network connectivity. No official patch or fix is currently available; mitigation relies on configuration changes.
CVE-2026-10805: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Red Hat Red Hat Enterprise Linux 8
Description
A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager.
CVSS v3.1
Score 6.7medium
Affected software
Red Hat
Red Hat Enterprise Linux 8
Red Hat
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red Hat
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Red Hat
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red Hat
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
Red Hat
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
Red Hat
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Red Hat
Red Hat Enterprise Linux 9
Red Hat
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Red Hat
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
Red Hat
Red Hat Enterprise Linux 9.6 Extended Update Support
Red Hat
Multicluster Engine for Kubernetes
Red Hat
Red Hat Enterprise Linux 10
Red Hat
Red Hat Enterprise Linux 6
Red Hat
Red Hat Enterprise Linux 7
Red Hat
Red Hat Enterprise Linux 8
Red Hat
Red Hat Enterprise Linux 9
Red Hat
Red Hat JBoss Enterprise Application Platform Expansion Pack
Red Hat
Red Hat OpenShift Container Platform 4
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability exists in NetworkManager's dhclient backend due to improper neutralization of special elements used in OS commands (OS command injection) when processing malformed MUD URLs. A local user with low privileges can escalate their privileges by exploiting this flaw, provided the system administrator has configured NetworkManager to use the dhclient backend. The default configuration uses an internal DHCP client and is not affected. Exploitation requires user interaction and has high attack complexity. The vulnerability impacts confidentiality, integrity, and availability by allowing unauthorized command execution, potentially leading to system compromise or denial of service.
Potential Impact
If exploited, an attacker with local access can execute unauthorized operating system commands with elevated privileges, potentially leading to full system compromise, data modification, or denial of service. However, exploitation requires a non-default configuration where NetworkManager is set to use dhclient, which is not enabled by default on Red Hat Enterprise Linux systems. Therefore, the risk is limited to systems with this explicit configuration change.
Mitigation Recommendations
Red Hat advises ensuring that NetworkManager is not configured to use the dhclient backend. The default configuration does not enable dhclient. If a custom configuration file such as /etc/NetworkManager/conf.d/00-dhcp.conf contains the line '[main] dhcp=dhclient', this line should be removed or commented out. After making this change, restart the NetworkManager service using 'sudo systemctl restart NetworkManager'. Note that restarting NetworkManager will temporarily disrupt network connectivity. No official patch or fix is currently available; mitigation relies on configuration changes.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-06-04T05:10:00.738Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-10805","vendor":"Red Hat"}]
Threat ID: 6a210e2ee29bf47b506be551
Added to database: 06/04/2026, 05:33:34 UTC
Last enriched: 08/06/2026, 19:00:22 UTC
Last updated: 09/13/2026, 22:01:31 UTC
Views: 128
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.