A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged user can create and activate their own L2TP VPN profile containing a newline-injected leftupdown directive; pluto executes that command as root when the IKE security association is established, resulting in local privilege escalation. This is the same bug class as CVE-2018-10900 (NetworkManager-vpnc).
{
"cna_assigner": "fedora",
"cwe_ids": [
"CWE-88"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19624.json"
}{
"extracted_events": [
{
"introduced": "1.0.0"
},
{
"fixed": "1.0.16"
},
{
"introduced": "1.2.0"
},
{
"fixed": "1.2.22"
},
{
"introduced": "1.8.0"
},
{
"fixed": "1.8.10"
},
{
"introduced": "1.20.0"
},
{
"fixed": "1.20.24"
},
{
"introduced": "1.52.0"
},
{
"fixed": "1.52.4"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19624.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "13964438800715637485908274376023140312",
"length": 1924
},
"id": "CVE-2026-19624-1d69c2a3",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/nm-l2tp/networkmanager-l2tp/commit/95b6b46f48a0c9eabc79272cd313f219110ef91c",
"target": {
"file": "src/nm-l2tp-service.c",
"function": "handle_need_secrets"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "17669389332226560085624569025636570449",
"length": 1578
},
"id": "CVE-2026-19624-54fce860",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/nm-l2tp/networkmanager-l2tp/commit/95b6b46f48a0c9eabc79272cd313f219110ef91c",
"target": {
"file": "src/nm-l2tp-service.c",
"function": "validate_one_property"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"56729098099101703669903456529156069862",
"259250658643546897148582399276164297545",
"65111469976273515679866129474813356740",
"255306186292428187255093885943112397075",
"45908978728976663032842464259496126954",
"23822332537171051940890045257615178007",
"74716615936422012258224446761907090011",
"258992435164776269446931223689317742243",
"122006297347136451589395573509347081141",
"129312901362782005781301822372212109375",
"279540930461600882574606516120782951896",
"276414130930462079905725293414921215373",
"34589620706289540010224129368596713432",
"198936859782390531681175885044565144982",
"243052109151728983703982316010310873881",
"213061877386431798874054128151116495358",
"299278647089658727051815064060003491750"
],
"threshold": 0.9
},
"id": "CVE-2026-19624-9113a730",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/nm-l2tp/networkmanager-l2tp/commit/95b6b46f48a0c9eabc79272cd313f219110ef91c",
"target": {
"file": "src/nm-l2tp-service.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "69003167894437558481569827080944388652",
"length": 20801
},
"id": "CVE-2026-19624-bf0efa55",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/nm-l2tp/networkmanager-l2tp/commit/95b6b46f48a0c9eabc79272cd313f219110ef91c",
"target": {
"file": "src/nm-l2tp-service.c",
"function": "nm_l2tp_config_write"
}
}
]
"2026-09-16T08:11:33Z"