CVE-2026-19685

critical EU-CRITICAL
EUVD alias: EUVD-2026-64957
Assigned by CNA: redhat
Published 2026-08-24 · Modified 2026-08-24
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4 NEW
not yet in upstream
VIR risk
9.8

Description

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2026-19685 NameCVE-2026-19685 SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed packages The table below lists information on source packages. Source PackageReleaseVersionStatus network-manager (PTS)bullseye1.30.6-1+deb11u1vulnerable…

CVE-2026-19685

NameCVE-2026-19685
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
network-manager (PTS)bullseye1.30.6-1+deb11u1vulnerable
bookworm1.42.4-1+deb12u1vulnerable
trixie1.52.1-1fixed
forky, sid1.58.0-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
network-managersourcetrixie(not affected)
network-managersource(unstable)(unfixed)

Notes

[trixie] - network-manager <not-affected> (Fix for CVE-2025-9615 not applied)
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2513
Introduced with: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/e85cc46d0b36cdba50fe8411cc93d55a49ebfccf (1.57.1-dev)
The introducing commit is part of the patchseries for CVE-2025-9615
Fixed by: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/a8e87381a3e70060abd721d9a347f42b2ba68e6e

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[trixie] - network-manager <not-affected> (Fix for CVE-2025-9615 not applied)https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2513Introduced with: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/e85cc46d0b36cdba50fe8411cc93d55a49ebfccf (1.57.1-dev)The introducing commit is part of the patchseries for CVE-2025-9615Fixed by: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/a8e87381a3e70060abd721d9a347f42b2ba68e6e

OS impact

debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Fixed 0
sid Affected
forky Affected
bullseye Affected
bookworm Affected

References

CWEs

CWE-863

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.