CVE-2026-19624 | Fedora NetworkManager-l2tp VPN Connection ipsec.conf vpn.data/vpn.secrets os command injection

SecurityVulns

A vulnerability was found in Fedora NetworkManager-l2tp. It has been rated as very critical. Impacted is an unknown function of the file ipsec.conf of the component VPN Connection. Performing a manipulation of the argument vpn.data/vpn.secrets results in os command injection.

This vulnerability was named CVE-2026-19624. The attack needs to be approached locally. There is no available exploit.

To fix this issue, it is recommended to deploy a patch.VulDB Recent EntriesRead More