Junglewise Threat Intelligence

CVE-2026-19685: NetworkManager private user restriction bypass in 802.1X

CVE-2026-19685 · Severity: high · CVSS 7.1 · Published 2026-08-24

Vendors: Gnome.

Executive brief

NetworkManager is a system component that manages network connections on Linux systems. This vulnerability allows a local user with access to network settings to bypass server certificate validation for WPA-Enterprise (802.1X) WiFi connections by pointing to an attacker-controlled directory. An attacker could intercept login credentials or perform a man-in-the-middle attack on enterprise WiFi networks, compromising user authentication and potentially gaining access to corporate resources.

Technical details

NetworkManager failed to apply private_user restrictions to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties, representing an incomplete fix for CVE-2025-9615. The vulnerability allows an unprivileged local user with the settings.modify.own polkit permission to redirect a private WPA-Enterprise connection profile's CA path to an attacker-controlled directory, bypassing server certificate validation. The attack vector is local with low privilege requirements and no user interaction needed; exploitation requires an active local session. An attacker can perform a man-in-the-middle attack via a rogue access point to steal EAP credentials. The upstream fix (commit a8e87381) was released in NetworkManager 1.58.1 and later versions, rejecting ca-path properties on private connections and requiring ca-cert or system-ca-certs instead.

Affected products

  • GNOME NetworkManager before 1.58.1

Timeline

  • 2026-08-24: disclosed
  • 2026: patched: Fixed in NetworkManager 1.58.1 and later 1.60 development snapshots

References