CVE WATCH / VULNERABILITY DETAIL

CVE-2026-91838

HIGHCVSS 7.8NVD feed

Published 25 September 2026 · tracked since 26 September 2026

Description

A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields such as CA certificate or proxy settings. These unescaped chara

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-91838 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-91838

HIGHCVSS 7.8NVD feed

Published 25 September 2026 · tracked since 26 September 2026

Description

A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields such as CA certificate or proxy settings. These unescaped chara

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]