---
id: CVE-2026-91837
title: >-
  A flaw was found in NetworkManager-iodine, the iodine VPN plugin for
  NetworkManager
summary: >-
  A flaw was found in NetworkManager-iodine, the iodine VPN plugin for
  NetworkManager. A local unprivileged user can exploit a vulnerability in how
  the 'nameserver' setting is processed when establishing an iodine VPN
  connection. By embedd…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: GNOME
product: network-manager-iodine
affected:
  - network-manager-iodine < *
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T17:17:18.983'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91837'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-91837'
    label: patrick@puiterwijk.org
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2533634'
    label: patrick@puiterwijk.org
  - url: 'https://gitlab.gnome.org/GNOME/network-manager-iodine/-/work_items/4'
    label: patrick@puiterwijk.org
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-25T16:39:28.774813Z'
ingestedAt: '2026-09-25T17:13:14.019Z'
---

## Overview

A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager. A local unprivileged user can exploit a vulnerability in how the 'nameserver' setting is processed when establishing an iodine VPN connection. By embedding shell metacharacters (special characters that can execute commands) in the 'nameserver' value, an attacker can inject and execute arbitrary commands. These commands run with root privileges before the application drops its elevated permissions, leading to local privilege escalation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
