CVE-2026-91838: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in GNOME NetworkManager-sstp
A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields such as CA certificate or proxy settings. These unescaped characters are then processed by the `pppd` daemon, which runs with root privileges, allowing the attacker to execute arbitrary commands with elevated permissions when a malicious VPN connection is activated.
AI Analysis
Technical Summary
This vulnerability exists in NetworkManager-sstp, where unescaped shell metacharacters embedded by a local unprivileged user in VPN connection profile fields (such as CA certificate or proxy settings) are passed to the pppd daemon running as root. This improper neutralization of special elements leads to OS command injection, enabling arbitrary command execution with root privileges upon activation of a malicious VPN connection. The vulnerability has a CVSS 3.1 score of 7.8 (high severity). Red Hat's advisory states that no currently supported Red Hat products are affected. The vulnerability requires local access and activation of a malicious VPN profile.
Potential Impact
Successful exploitation allows a local unprivileged user to execute arbitrary commands with root privileges, potentially leading to full system compromise including unauthorized code execution, data modification, denial of service, and hiding of malicious activities. The attack vector requires local user interaction to activate a crafted VPN connection profile.
Mitigation Recommendations
Red Hat states that no currently supported Red Hat products are affected by this vulnerability. If NetworkManager-sstp is not required, removing the package eliminates the attack vector. This can be done using the command: sudo dnf remove NetworkManager-sstp. Removal may impact functionality relying on SSTP VPN connections. There is no official patch or fix indicated in the advisory; users should monitor vendor advisories for updates.
CVE-2026-91838: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in GNOME NetworkManager-sstp
Description
A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields such as CA certificate or proxy settings. These unescaped characters are then processed by the `pppd` daemon, which runs with root privileges, allowing the attacker to execute arbitrary commands with elevated permissions when a malicious VPN connection is activated.
CVSS v3.1
Score 7.8high
Affected software
GNOME
NetworkManager-sstp
pkg:github/gnome/network-manager-sstpRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability exists in NetworkManager-sstp, where unescaped shell metacharacters embedded by a local unprivileged user in VPN connection profile fields (such as CA certificate or proxy settings) are passed to the pppd daemon running as root. This improper neutralization of special elements leads to OS command injection, enabling arbitrary command execution with root privileges upon activation of a malicious VPN connection. The vulnerability has a CVSS 3.1 score of 7.8 (high severity). Red Hat's advisory states that no currently supported Red Hat products are affected. The vulnerability requires local access and activation of a malicious VPN profile.
Potential Impact
Successful exploitation allows a local unprivileged user to execute arbitrary commands with root privileges, potentially leading to full system compromise including unauthorized code execution, data modification, denial of service, and hiding of malicious activities. The attack vector requires local user interaction to activate a crafted VPN connection profile.
Mitigation Recommendations
Red Hat states that no currently supported Red Hat products are affected by this vulnerability. If NetworkManager-sstp is not required, removing the package eliminates the attack vector. This can be done using the command: sudo dnf remove NetworkManager-sstp. Removal may impact functionality relying on SSTP VPN connections. There is no official patch or fix indicated in the advisory; users should monitor vendor advisories for updates.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- fedora
- Date Reserved
- 2026-09-15T08:28:01.333Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-91838","vendor":"Red Hat"}]
Threat ID: 6ab6b765f7a7c541061a1e6c
Added to database: 09/25/2026, 18:03:17 UTC
Last enriched: 09/25/2026, 18:17:40 UTC
Last updated: 09/25/2026, 18:34:18 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.