OurCVEs
Register
Back to feed
High
DEBIAN-CVE-2026-91839

Published Sep 25, 2026

CVSS

7.8

HIGH

EPSS

Exploit Prediction Scoring System — the modeled probability of in-the-wild exploitation in the next 30 days.
—

Affected packages

0
Summary

A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local unprivileged user can exploit this by crafting a malicious VPN profile to inject additional configuration directives. This can lead to arbitrary code execution with root privileges when the crafted VPN connection is activated.

Developer impact

Recommended action

Affected packages
Sources