Skip to content
Critical CVE-2026-93337 in NetworkManager-l2tp Allows Root Code Execution

Critical CVE-2026-93337 in NetworkManager-l2tp Allows Root Code Execution

First seen 18 Sep 2026, 01:22 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 02:00 UTC
  • CVE-2026-93337 allows local users to escalate privileges to root via NetworkManager-l2tp.
  • The vulnerability affects Linux systems where users can create VPN connections.
  • A proof-of-concept for the exploit has been developed, indicating high risk.

A vulnerability identified as CVE-2026-93337 in NetworkManager-l2tp permits local users to exploit improper input validation of VPN properties, specifically mru and mtu. This flaw enables attackers to inject arbitrary pppd directives, leading to arbitrary code execution with root privileges. The issue affects Linux endpoints and servers where non-administrative users can create VPN connections. The vulnerability has been confirmed on Debian 13 and is considered a high-risk local privilege escalation. A proof-of-concept demonstrating the exploit has been developed, indicating reliable exploitation potential. Administrators are urged to apply patches promptly and restrict VPN connection creation to trusted users until a fix is implemented. Monitoring for unusual changes in PPP options files is also recommended. The vulnerability was published on September 17, 2026, and is currently not confirmed to be actively exploited in the wild.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-17
CVE-2026-93337 published
CVE-2026-93337 was published, detailing a vulnerability in NetworkManager-l2tp allowing local privilege escalation.
Redpacketsecurity
2026-09-18
Exploit confirmed with PoC
A proof-of-concept demonstrating the exploit's effectiveness has been developed and shared privately with maintainers.
github.com
2026-09-18
Urgent remediation recommended
Security advisories recommend immediate patching and restricting VPN connection creation to administrators.
Redpacketsecurity

More articles in this cluster (3)

Following this threat?

Track CVE-2026-93337 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed