Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-19685: NetworkManager allows local user to bypass Wi‑Fi security check
CVE-2026-19685 · published 10 days ago
Summary
The NetworkManager program on Linux does not properly limit a setting that tells the system where to look for trusted Wi‑Fi authentication files. This lets a regular user point a secure Wi‑Fi (WPA‑Enterprise) profile to a folder they control, causing the system to skip the verification of the network’s identity and potentially expose login credentials to a rogue access point. Apply the latest vendor updates and limit user permissions or avoid using this configuration option until it is fixed.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | red hat | red hat enterprise linux 10 | All versions |
| – | red hat | red hat enterprise linux 6 | All versions |
| – | red hat | red hat enterprise linux 7 | All versions |
| – | red hat | red hat enterprise linux 8 | All versions |
| – | red hat | red hat enterprise linux 9 | All versions |
| – | red hat | red hat hardened images | All versions |
| – | red hat | red hat openshift container platform 4 | All versions |
| Debian:11 | debian | network-manager | All versions |
| Debian:12 | debian | network-manager | All versions |
| Debian:13 | debian | network-manager | All versions |
| Debian:14 | debian | network-manager | All versions |
| Ubuntu:16.04:LTS | canonical | network-manager | All versions |
| Ubuntu:18.04:LTS | canonical | network-manager | All versions |
| Ubuntu:20.04:LTS | canonical | network-manager | All versions |
| Ubuntu:22.04:LTS | canonical | network-manager | All versions |
| Ubuntu:24.04:LTS | canonical | network-manager | All versions |
| Ubuntu:26.04:LTS | canonical | network-manager | All versions |
Original advisory text
NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileg...
NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.
References
- https://security-tracker.debian.org/tracker/CVE-2026-19685 Vendor Advisory
- https://redhat.atlassian.net/browse/PSIRTSUPT-20440
- https://bugzilla.redhat.com/show_bug.cgi?id=2515042 issue-tracking x_refsource_REDHAT
- https://nvd.nist.gov/vuln/detail/CVE-2026-19685 Vendor Advisory
- https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/e85cc46d0b... Patch
- https://access.redhat.com/downloads/content/package-browser/ URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19685... Vendor Advisory
- https://ubuntu.com/security/CVE-2026-19685 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-19685 Third Party Advisory
- https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/25... Third Party Advisory
- https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/a8e87381a3...
- https://access.redhat.com/security/cve/CVE-2026-19685 vdb-entry x_refsource_REDHAT
Severity
9.8
Critical
CVSS 3.1: 9.8 (MITRE)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-863Incorrect Authorization
Timeline
Published24 Aug 2026
Updated2 Sep 2026
First seen22 Aug 2026
Sources
DEBIAN-CVE-2026-19685 · OSV
CVE-2026-19685 · NVD
CVE-2026-19685 · MITRE
CVE-2026-19685 · OSV
UBUNTU-CVE-2026-19685 · OSV
Monitor software like this
Free during beta