Skip to content
CVE Alert: CVE-2026-93337 – nm-l2tp – NetworkManager

CVE Alert: CVE-2026-93337 – nm-l2tp – NetworkManager

Redpacketsecurity admin September 18, 2026

NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu property values containing trailing non-numeric content after a valid integer. Attackers can exploit the verbatim write of unvalidated strings into the pppd options file via write_config_option() to inject the plugin directive, causing the privileged pppd process to load an attacker-controlled shared object and achieve arbitrary code execution as root.

High-risk local privilege escalation requiring prompt remediation, although the supplied data does not confirm active exploitation, KEV listing, SSVC exploitation, PoC availability or an EPSS estimate.

A permitted local user may convert ordinary VPN configuration access into root-level code execution, enabling credential theft, tampering, persistence and disruption of the host. This is particularly relevant on shared workstations, jump hosts and multi-user systems where VPN access is delegated beyond administrators.

### Most likely attack path

The path is local (AV:L), low complexity (AC:L), needs limited privileges (PR:L), requires no user interaction (UI:N), and has unchanged scope. An attacker who can create or modify a VPN connection supplies crafted numeric-looking values, causes a privileged VPN process to load an attacker-controlled plugin, and obtains root execution; scope remains on the host, but that access may expose credentials and trusted network connectivity.

### Who is most exposed

Linux endpoints and servers using the affected VPN integration, especially environments granting non-administrators permission to create VPN connections through NetworkManager. Shared engineering systems, remote-access gateways and bastion hosts warrant particular attention.

Alert on unexpected changes to PPP options files and plugin directives.

Monitor privileged VPN or PPP processes loading libraries from user-writable paths.

Review NetworkManager connection-property changes by non-administrators.

Hunt for unusual root child processes, persistence files or outbound connections after VPN activation.

### Mitigation and prioritisation

Apply the vendor’s fixed release promptly; prioritise internet-connected or shared hosts.

Until patched, restrict VPN-connection creation to administrators and remove unnecessary local access.

Prevent privileged processes from loading libraries from writable locations using MAC policies where feasible.

Validate and stage the update across VPN-dependent systems, retaining rollback plans and testing connection compatibility.

Reassess urgency when exploitation, PoC or EPSS intelligence becomes available.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.