Junglewise Threat Intelligence

CVE-2026-10805: NetworkManager privilege escalation in dhclient backend

CVE-2026-10805 · Severity: medium · CVSS 6.7 · Published 2026-06-04

Vendors: Red Hat.

Executive brief

A security vulnerability in NetworkManager, a common tool for managing network connections on Linux systems, could allow a local user to gain administrative privileges. By providing a specially crafted web address (URL) during network configuration, an attacker can trick the system into running unauthorized scripts. This issue only affects systems where an administrator has manually changed the default settings to use the 'dhclient' backend.

Technical details

An OS command injection vulnerability (CWE-78) exists in the NetworkManager dhclient backend. The flaw is triggered during the processing of malformed Manufacturer Usage Description (MUD) URLs provided via DHCP. A local attacker with low privileges can exploit this to execute arbitrary scripts with elevated privileges. This vulnerability is not present in default configurations; it requires an administrator to have explicitly configured NetworkManager to use the dhclient backend instead of the internal DHCP client. Exploitation also requires some level of user interaction or specific environmental conditions (AC:H/UI:R).

Affected products

  • Red Hat NetworkManager unspecified

Timeline

  • 2026-06-04: disclosed: Initial disclosure via Red Hat and NVD
  • 2026-06-04: advisory

References