Junglewise Threat Intelligence

CVE-2026-19624: NetworkManager-l2tp unescaped configuration injection in ipsec.conf

CVE-2026-19624 · Severity: high · CVSS 7.8 · Published 2026-09-14

Executive brief

NetworkManager-l2tp is a plugin that enables L2TP VPN connections in Linux. The plugin fails to properly escape user-controlled VPN settings before writing them to the ipsec.conf configuration file, which is executed with root privileges. An attacker with local access can inject arbitrary commands into this file, leading to privilege escalation when the VPN connection is activated.

Technical details

The vulnerability is a command injection flaw in NetworkManager-l2tp's handling of VPN connection properties. The plugin writes vpn.data and vpn.secrets values directly into the ipsec.conf file without proper escaping or sanitization. An attacker can craft a malicious L2TP VPN profile containing newline characters and shell metacharacters in connection properties (specifically the leftupdown directive), which allows injection of arbitrary commands. When pluto (the IKE daemon) loads the configuration and establishes a security association, the injected command executes as root. This is the same vulnerability class as CVE-2018-10900 found in NetworkManager-vpnc. Only a local, unprivileged user account is required; no network access is needed.

Affected products

  • NetworkManager-l2tp NetworkManager-l2tp

Timeline

  • 2026-09-14: disclosed

References

Related threats