HIGH
Fedora
CVE published 2026-09-14
CVE-2026-19624
A local unprivileged user can create and activate their own L2TP VPN profile containing a newline-injected leftupdown directive; pluto executes that command as root when the IKE security association is established, resulting in local privilege escalation. This flaw in NetworkManager-l2tp allows the execution of arbitrary commands as root, potentially leading to a full system compromise. The vulnerability [truncated]