GHSA-p2g6-ffcc-pqqvHighCVSS 7.8

A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to...

Published
September 25, 2026
Last Modified
September 25, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration to execute an arbitrary program with root privileges when the malicious VPN connection is activated.

🔗 References (5)