Sceawere

Vulnerability Detail

CVE-2026-19685UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

NetworkManager Incomplete Fix CA Path Bypass

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
Red Hat
Product
Red Hat Enterprise Linux 10
Attack Type
Incorrect Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-24T17:17:21.907Z",
  "pubdate": "2026-08-24T17:17:21.907Z",
  "executiveSummary": "This vulnerability represents an incomplete fix for CVE-2025-9615 affecting NetworkManager, specifically involving the improper application of the private_user restriction to directory-valued connection properties. The flaw allows an unprivileged local attacker to manipulate connection profiles for WPA-Enterprise and 802.1X networks by altering certificate authority (CA) paths.\nThe primary impact of this security deficiency is the complete bypass of server certificate validation during the authentication handshake. By redirecting the 802-1x.ca-path and phase2-ca-path properties to an attacker-controlled directory, a malicious actor can facilitate credential theft.\nThe affected product is NetworkManager. Exploitation requires local access to the system with unprivileged user rights, enabling the modification of connection profile configurations.\nThe risk implication is significant within multi-tenant or shared local environments where unauthorized profile manipulation can lead to credential exposure during network connection attempts against rogue access points.",
  "technicalDetails": "The root cause of this vulnerability lies in the insufficient enforcement of the private_user security restriction within NetworkManager. Specifically, the validation logic fails to correctly restrict directory-valued connection properties associated with enterprise wireless configurations, namely 802-1x.ca-path and phase2-ca-path.\nDuring the parsing and application of connection profiles, NetworkManager permits the specification of custom file system paths for Certificate Authority verification without adequately validating whether the invoking user possesses the privileges required to reference arbitrary directories or if the targeted path violates security boundaries designed for unprivileged users.\nThe attack flow proceeds as follows: First, an unprivileged local user accesses the NetworkManager connection profile storage or interfaces to modify an existing private WPA-Enterprise or 802.1X connection profile. Second, the user updates the 802-1x.ca-path and phase2-ca-path properties to point toward an attacker-controlled directory containing malicious or absent certificate validation assets. Third, when NetworkManager attempts to establish a connection to the enterprise network, the Extensible Authentication Protocol (EAP) negotiation initiates. Fourth, due to the misdirected CA path, the EAP supplicant fails to properly validate the authenticity of the authentication server presented by the network infrastructure. Fifth, a rogue access point mimics the legitimate enterprise network, exploiting the bypassed certificate verification to establish a fraudulent TLS tunnel or authentication exchange. Finally, the client transmits enterprise authentication credentials to the rogue access point, resulting in credential theft.\nThe vulnerable components are the connection property validation routines within NetworkManager that handle 802.1X and WPA-Enterprise configuration parsing. The vulnerability requires local access and unprivileged user capabilities on the host system, but requires the victim or system to attempt connection authentication within range of a rogue access point to complete the exploitation loop."
}
CVE-2026-19685: NetworkManager Incomplete Fix CA Path Bypass (CRITICAL Severity, CVSS: 9.8) - Sceawere