A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

SELinux is shipped out of the box in targeted enforcing mode, which prevents processes from having unwanted permissions and mitigates this attack.

History

Mon, 26 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 26 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.
Title Networkmanager: networkmanager file access
First Time appeared Redhat
Redhat enterprise Linux
Redhat openshift
Weaknesses CWE-281
CPEs cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openshift
References
Metrics cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-01-26T20:15:40.818Z

Reserved: 2025-08-28T15:52:57.853Z

Link: CVE-2025-9615

cve-icon Vulnrichment

Updated: 2026-01-26T20:15:32.138Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-26T20:16:09.207

Modified: 2026-01-27T14:59:34.073

Link: CVE-2025-9615

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses