CVE-2026-91839High· 7.8▾ MidnightPoC availableA flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local unprivil…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 42.9 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Exploit / PoC code exists
A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local unprivileged user can exploit this by crafting a malicious VPN profile to inject additional configuration directives. This can lead to arbitrary code execution with root privileges when the crafted VPN connection is activated.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-91841High· 7.8A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager
CVE-2026-91840High· 7.8A flaw was found in NetworkManager-vpnc
CVE-2026-88924High· 7.0Gvfs: gvfs-admin socket ownership race permits local root
CVE-2026-58014High· 7.3A flaw was found in GLib
CVE-2026-58011Medium· 6.5A flaw was found in GLib
CVE-2025-7425High· 7.8A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management