Security Advisory

CVE-2026-10805

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-04 05:21:34
Last updated 2026-08-24 08:10:12
Assigner redhat
CVSS score 6.7
State PUBLISHED

Description

A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager.