{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/networkmanager-l2tp/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:networkmanager-l2tp_project:networkmanager-l2tp:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-93337"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["NetworkManager-l2tp"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","linux","cve"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eCVE-2026-93337 describes an improper input validation vulnerability within NetworkManager-l2tp that facilitates privilege escalation. Local users who possess the necessary permissions to create VPN connections can manipulate the 'mru' or 'mtu' properties by appending non-numeric characters to a valid integer. The application's 'write_config_option()' function improperly validates this input and writes the entire string verbatim into the 'pppd' options configuration file.\u003c/p\u003e\n\u003cp\u003eBecause the 'pppd' process runs with root privileges, this injection vector allows an attacker to insert a 'plugin' directive into the configuration file. When the 'pppd' daemon subsequently starts or reloads its configuration, it interprets this injected directive and loads an attacker-specified shared object file. This enables an unprivileged local attacker to achieve arbitrary code execution in the context of the root user, significantly impacting system integrity and confidentiality.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a local user with standard VPN configuration permissions to escalate privileges to root. This impacts any Linux system utilizing NetworkManager-l2tp, potentially leading to full system compromise, exfiltration of sensitive credentials, or the installation of persistent rootkits.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAudit system configurations for users with VPN connection creation permissions and restrict access to strictly necessary accounts.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized modifications to files located in /etc/ppp/options or other pppd configuration directories.\u003c/li\u003e\n\u003cli\u003eUpdate NetworkManager-l2tp to the patched version as soon as provided by the distribution vendor to mitigate the input validation flaw in 'write_config_option()'.\u003c/li\u003e\n\u003cli\u003eImplement endpoint monitoring to detect unusual 'pppd' process invocations, particularly those referencing non-standard shared object files or unexpected configuration paths.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-17T21:59:20Z","date_published":"2026-09-17T21:59:20Z","id":"https://feed.craftedsignal.io/briefs/2026-09-networkmanager-l2tp-rce/","summary":"An improper input validation vulnerability in NetworkManager-l2tp (CVE-2026-93337) allows local users with VPN creation permissions to inject malicious directives into the pppd configuration, leading to arbitrary code execution as root.","title":"Local Privilege Escalation in NetworkManager-l2tp via pppd Directive Injection","url":"https://feed.craftedsignal.io/briefs/2026-09-networkmanager-l2tp-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - NetworkManager-L2tp","version":"https://jsonfeed.org/version/1.1"}