SUSE NetworkManager Vulnerabilities Lead to Important Local Privilege Escalation Fixes

SUSE NetworkManager Vulnerabilities Lead to Important Local Privilege Escalation Fixes

First seen 10 Sep 2026, 15:20 UTC Linuxsecurity 57.9

Article Content

Browse articles
ThreatCluster

SUSE has released updates for NetworkManager addressing two critical vulnerabilities: CVE-2026-10805 and CVE-2026-19685. CVE-2026-10805 allows local privilege escalation through malformed MUD URLs in the dhclient backend, while CVE-2026-19685 permits a bypass of WPA-Enterprise server certificate validation due to missing user ownership checks for 802.1X directory properties. Both vulnerabilities affect SUSE Linux Micro versions 6.0 and 6.2. The patches are available via SUSE's recommended installation methods, including YaST and zypper. The vulnerabilities were published on June 4 and August 24, 2026, respectively. Security professionals are urged to apply the patches as soon as possible to mitigate risks. The updates are rated as important, indicating a significant threat to affected systems.

Key Points: • Two critical vulnerabilities in SUSE NetworkManager have been patched. • CVE-2026-10805 and CVE-2026-19685 affect SUSE Linux Micro versions 6.0 and 6.2. • Immediate patching is recommended to prevent potential exploitation.

Ask AI about this cluster

Timeline

2026-06-04
CVE-2026-10805 published
Local privilege escalation vulnerability via malformed MUD URLs in dhclient backend disclosed.
Linuxsecurity
2026-08-24
CVE-2026-19685 published
Missing user ownership checks for 802.1X properties allow WPA-Enterprise certificate validation bypass disclosed.
Linuxsecurity
2026-09-06
Patch released for NetworkManager
SUSE released updates to address CVE-2026-10805 and CVE-2026-19685 for Linux Micro 6.2.
Linuxsecurity
2026-09-09
Patch released for NetworkManager 6.0
SUSE released updates to address vulnerabilities for Linux Micro 6.0.
Linuxsecurity