USN-8806-1: NetworkManager vulnerability
Publication date
23 September 2026
Overview
Fraudulent security certificates could allow sensitive information to be exposed when connecting to a WPA-Enterprise network.
Releases
Packages
- network-manager - Network connection manager
Details
It was discovered that NetworkManager did not properly restrict the
ca-path and phase2-ca-path certificate authority settings for private
(single-user) 802.1X network connections. An attacker could use this issue
to point their own private 802.1X connection profile at a directory under
their control, causing NetworkManager to trust an attacker-chosen
certificate authority and potentially exposing network credentials via a
rogue authentication server.
It was discovered that NetworkManager did not properly restrict the
ca-path and phase2-ca-path certificate authority settings for private
(single-user) 802.1X network connections. An attacker could use this issue
to point their own private 802.1X connection profile at a directory under
their control, causing NetworkManager to trust an attacker-chosen
certificate authority and potentially exposing network credentials via a
rogue authentication server.
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
| Ubuntu Release | Package Version | ||
|---|---|---|---|
| 26.04 LTS resolute | network-manager – 1.54.3-2ubuntu3.1 | ||
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.