Back to overview

CVE-2026-10805

MEDIUM
6.7
CVSS 3.1
Description
A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager.

Metadata

CVE ID
CVE-2026-10805
State
PUBLISHED
Assigner
redhat
Reserved
2026-06-04 05:10 UTC
Published
2026-06-04 05:21 UTC
Last updated
2026-06-04 12:39 UTC
Primary CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Co…
Vendor / Product
Red Hat / Multicluster Engine for Kubernetes
Sources
cve.org  ·  NVD

Severity & Metrics

6.7 MEDIUM CVSS 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (26)
VendorProductPlatformVersions
Red Hat Multicluster Engine for Kubernetes
Red Hat Red Hat Enterprise Linux 10
Red Hat Red Hat Enterprise Linux 10
Red Hat Red Hat Enterprise Linux 10
Red Hat Red Hat Enterprise Linux 10
Red Hat Red Hat Enterprise Linux 6
Red Hat Red Hat Enterprise Linux 6
Red Hat Red Hat Enterprise Linux 7
Red Hat Red Hat Enterprise Linux 7
Red Hat Red Hat Enterprise Linux 8
Red Hat Red Hat Enterprise Linux 8
Red Hat Red Hat Enterprise Linux 9
Red Hat Red Hat Enterprise Linux 9
Red Hat Red Hat Enterprise Linux 9
Red Hat Red Hat Enterprise Linux 9
Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack
Red Hat Red Hat OpenShift Container Platform 4
Red Hat Red Hat OpenShift Container Platform 4
Red Hat Red Hat OpenShift Container Platform 4
Red Hat Red Hat OpenShift Container Platform 4
Red Hat Red Hat OpenShift Container Platform 4
Red Hat Red Hat OpenShift Container Platform 4
Red Hat Red Hat OpenShift Container Platform 4
Red Hat Red Hat OpenShift Container Platform 4
Red Hat Red Hat OpenShift Container Platform 4
Red Hat Red Hat OpenShift Container Platform 4
Weakness (CWE)
CWESourceDescription
CWE-78 cna Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS scores (1)
ScoreSeverityVersionSourceVector
6.7 MEDIUM 3.1 cna CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Back to overview