CVE-2026-19685
Publication date 24 August 2026
Last updated 21 September 2026
Ubuntu priority
Cvss 3 Severity Score
Description
NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| network-manager | 26.04 LTS resolute |
Vulnerable
|
| 24.04 LTS noble |
Not affected
|
|
| 22.04 LTS jammy |
Not affected
|
|
| 20.04 LTS focal |
Not affected
|
|
| 18.04 LTS bionic |
Not affected
|
|
| 16.04 LTS xenial |
Not affected
|
Notes
yomonokio
only network-manager >= 1.57.1-dev (which introduced the CVE-2025-9615 private_user blob-passing restriction, commit e85cc46d0b36) can reach the ca-path/phase2-ca-path gap this CVE describes. xenial/bionic/focal/jammy/noble never received that fix and are not-affected; only resolute (1.54.3-2ubuntu3) has the private_user restriction without covering ca-path, so it is needed. Same reasoning as Debian's bookworm/bullseye/trixie not-affected verdicts. devel (release codename "stonking", 1.58.1-1ubuntu3) already ships the fix upstream; confirmed via source inspection.
Severity score breakdown
CVSS version: CVSS v3.0
Base score
7.1 · High
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N