Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-19685: NetworkManager allows local user to bypass Wi‑Fi security check

CVE-2026-19685 · published 10 days ago
Summary

The NetworkManager program on Linux does not properly limit a setting that tells the system where to look for trusted Wi‑Fi authentication files. This lets a regular user point a secure Wi‑Fi (WPA‑Enterprise) profile to a folder they control, causing the system to skip the verification of the network’s identity and potentially expose login credentials to a rogue access point. Apply the latest vendor updates and limit user permissions or avoid using this configuration option until it is fixed.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
Ecosystem VendorProductAffected versions
red hat red hat enterprise linux 10 All versions
red hat red hat enterprise linux 6 All versions
red hat red hat enterprise linux 7 All versions
red hat red hat enterprise linux 8 All versions
red hat red hat enterprise linux 9 All versions
red hat red hat hardened images All versions
red hat red hat openshift container platform 4 All versions
Debian:11 debian network-manager All versions
Debian:12 debian network-manager All versions
Debian:13 debian network-manager All versions
Debian:14 debian network-manager All versions
Ubuntu:16.04:LTS canonical network-manager All versions
Ubuntu:18.04:LTS canonical network-manager All versions
Ubuntu:20.04:LTS canonical network-manager All versions
Ubuntu:22.04:LTS canonical network-manager All versions
Ubuntu:24.04:LTS canonical network-manager All versions
Ubuntu:26.04:LTS canonical network-manager All versions
Original advisory text
NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileg...
NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.
Severity
9.8 Critical
CVSS 3.1: 9.8 (MITRE)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-863Incorrect Authorization
Timeline
Published24 Aug 2026
Updated2 Sep 2026
First seen22 Aug 2026
Monitor software like this
Free during beta