Security Advisory

CVE-2026-10805

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-04 05:21:34
Last updated 2026-07-02 06:59:56
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager.