CVE WATCH / VULNERABILITY DETAIL

CVE-2026-91839

HIGHCVSS 7.8NVD feed

Published 25 September 2026 · tracked since 26 September 2026

Description

A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local unprivileged user can exploit this by crafting a malicious VPN profile

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-91839 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-91839

HIGHCVSS 7.8NVD feed

Published 25 September 2026 · tracked since 26 September 2026

Description

A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local unprivileged user can exploit this by crafting a malicious VPN profile

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]