OurCVEs
Register
Back to feed
High
DEBIAN-CVE-2026-91840

Published Sep 25, 2026

CVSS

7.8

HIGH

EPSS

Exploit Prediction Scoring System — the modeled probability of in-the-wild exploitation in the next 30 days.
—

Affected packages

0
Summary

A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration to execute an arbitrary program with root privileges when the malicious VPN connection is activated.

Developer impact

Recommended action

Affected packages
Sources