Moderate Vulnerability in Oracle NetworkManager Affects Multiple Linux Versions

Moderate Vulnerability in Oracle NetworkManager Affects Multiple Linux Versions

First seen 25 Aug 2026, 10:17 UTC Linuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

Oracle has released updates for NetworkManager to address CVE-2026-10805, a moderate vulnerability affecting Oracle Linux 8 and 9. The flaw could allow unauthorized access due to improper permission settings. The vulnerability was published on June 4, 2026, and affects various components of NetworkManager, including its dispatcher. Users are advised to update to the latest versions to mitigate the risk. Specific changes include dropping 777 permissions from the NetworkManager-dispatcher drop-in directory and adding a connectivity check via Oracle servers. Both Oracle Linux 8 and 9 are impacted, with different version numbers for the updates. The updates are available as RPM packages for affected systems. Administrators should prioritize applying these updates to ensure security.

Key Points: • CVE-2026-10805 affects Oracle Linux 8 and 9. • Updates include permission fixes and connectivity checks. • Users are urged to apply patches immediately to mitigate risks.

Timeline

2026-06-04
CVE-2026-10805 published
Oracle disclosed a moderate vulnerability in NetworkManager that could allow unauthorized access.
Linuxsecurity
2026-08-25
Oracle releases updates for NetworkManager
Oracle released patches for NetworkManager to fix CVE-2026-10805 in both Oracle Linux 8 and 9.
Linuxsecurity