{"id":"CVE-2026-19685","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-19685","summary":"NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows…","details":"NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.","published":"2026-08-24T17:17:21.907","modified":"2026-08-24T17:17:21.907","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-19685"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515042"},{"type":"WEB","url":"https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/e85cc46d0b36cdba50fe8411cc93d55a49ebfccf"},{"type":"WEB","url":"https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2513"},{"type":"WEB","url":"https://redhat.atlassian.net/browse/PSIRTSUPT-20440"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-24T17:17:21.907"}}