{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/802.1x/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-19685"},{"cvss":3.3,"id":"CVE-2025-9615"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["NetworkManager","Red Hat Enterprise Linux 10","Red Hat Enterprise Linux 6","Red Hat Enterprise Linux 7","Red Hat Enterprise Linux 8","Red Hat Enterprise Linux 9","Red Hat Hardened Images","Red Hat OpenShift Container Platform 4"],"_cs_severities":["high"],"_cs_tags":["credential-access","local-privilege-escalation","linux","networking","802.1x","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eNetworkManager contains an authorization vulnerability, tracked as CVE-2026-19685, stemming from an incomplete fix for CVE-2025-9615. The issue involves the failure to apply 'private_user' restrictions to the '802-1x.ca-path' and 'phase2-ca-path' connection properties. This vulnerability permits an unprivileged local user on systems running affected versions of NetworkManager to modify the CA path within a WPA-Enterprise (802.1X) connection profile. By pointing these paths to an attacker-controlled directory, a local user can successfully bypass server certificate validation. This defect is particularly critical in enterprise environments where 802.1X is the primary mechanism for network authentication, as it enables the capture of user credentials via rogue access point (AP) interception. The issue specifically impacts Red Hat Enterprise Linux 10 and related infrastructure, as identified by Red Hat.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains unprivileged access to a Linux system running an affected version of NetworkManager.\u003c/li\u003e\n\u003cli\u003eAttacker inspects existing WPA-Enterprise (802.1X) connection profiles.\u003c/li\u003e\n\u003cli\u003eAttacker uses NetworkManager command-line utilities (e.g., nmcli) to modify the '802-1x.ca-path' or 'phase2-ca-path' properties of a specific connection profile.\u003c/li\u003e\n\u003cli\u003eAttacker directs the modified CA path to a directory under their control containing a malicious, forged CA certificate.\u003c/li\u003e\n\u003cli\u003eAttacker deploys a rogue wireless access point configured to present the credentials required for the target network.\u003c/li\u003e\n\u003cli\u003eVictim system connects to the rogue AP, relying on the attacker-controlled CA path for validation.\u003c/li\u003e\n\u003cli\u003eNetworkManager successfully validates the connection against the attacker's forged certificate due to the bypass.\u003c/li\u003e\n\u003cli\u003eAttacker captures authentication credentials (e.g., EAP-MSCHAPv2 hashes) relayed by the victim during the 802.1X handshake.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the interception of sensitive network credentials in enterprise environments. By bypassing certificate validation, an attacker can perform man-in-the-middle attacks on WPA-Enterprise wireless networks. This leads to unauthorized network access and potential lateral movement within the victim's organization. The severity is elevated to 'critical' by some assessments due to the potential for total impact on confidentiality and integrity of network authentication.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrioritize updating NetworkManager packages across all systems running Red Hat Enterprise Linux 10 to the version containing the fix for CVE-2026-19685.\u003c/li\u003e\n\u003cli\u003eRestrict local access to system configuration files and NetworkManager connection profiles using standard Linux file permissions to prevent unauthorized modification by unprivileged users.\u003c/li\u003e\n\u003cli\u003eMonitor system logs for unexpected modifications to network connection profiles via 'nmcli' or direct file editing of '/etc/NetworkManager/system-connections/'.\u003c/li\u003e\n\u003cli\u003eReview 802.1X deployment configurations to ensure consistent enforcement of server-side certificate verification in high-security zones.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-24T22:03:19Z","date_published":"2026-08-24T22:03:19Z","id":"https://feed.craftedsignal.io/briefs/2026-08-networkmanager-ca-path-bypass/","summary":"An improper authorization vulnerability in NetworkManager allows unprivileged local users to bypass 802.1X server certificate validation, facilitating credential theft through rogue access points.","title":"NetworkManager Local Privilege Escalation and Credential Theft via CA Path Manipulation","url":"https://feed.craftedsignal.io/briefs/2026-08-networkmanager-ca-path-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - 802.1x","version":"https://jsonfeed.org/version/1.1"}