CVE-2026-19685

Publication date 24 August 2026

Last updated 24 September 2026


Ubuntu priority

Cvss 3 Severity Score

7.1 · High

Score breakdown

Description

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.

Read the notes from the security team

Status

Package Ubuntu Release Status
network-manager 26.04 LTS resolute
Fixed 1.54.3-2ubuntu3.1
24.04 LTS noble
Not affected
22.04 LTS jammy
Not affected
20.04 LTS focal
Not affected
18.04 LTS bionic
Not affected
16.04 LTS xenial
Not affected

Notes


yomonokio

only network-manager >= 1.57.1-dev (which introduced the CVE-2025-9615 private_user blob-passing restriction, commit e85cc46d0b36) can reach the ca-path/phase2-ca-path gap this CVE describes. xenial/bionic/focal/jammy/noble never received that fix and are not-affected; only resolute (1.54.3-2ubuntu3) has the private_user restriction without covering ca-path, so it is needed. Same reasoning as Debian's bookworm/bullseye/trixie not-affected verdicts. devel (release codename "stonking", 1.58.1-1ubuntu3) already ships the fix upstream; confirmed via source inspection.

Severity score breakdown

CVSS version: CVSS v3.0

Base score 7.1 · High

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

References

Related Ubuntu Security Notices (USN)

    • USN-8806-1
    • NetworkManager vulnerability
    • 23 September 2026

Other references


Access our resources on patching vulnerabilities