CVE-2025-9615Improper Preservation of Permissions in Project Network-manager

Severity
3.3LOWNVD
EPSS
0.0%
top 99.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 26

Description

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages1 packages

🔴Vulnerability Details

3
OSV
CVE-2025-9615: A flaw was found in NetworkManager2026-01-26
CVEList
Networkmanager: networkmanager file access2026-01-26
GHSA
GHSA-w24g-6mf8-65cj: A flaw was found in NetworkManager2026-01-26

📋Vendor Advisories

2
Red Hat
NetworkManager: NetworkManager File Access2025-12-12
Debian
CVE-2025-9615: network-manager - A flaw was found in NetworkManager. The NetworkManager package allows access to ...2025

🕵️Threat Intelligence

1
Wiz
CVE-2025-9615 Impact, Exploitability, and Mitigation Steps | Wiz

💬Community

1
Bugzilla
Adaptations for CVE-2025-9615 (NetworkManager)2026-01-10
CVE-2025-9615 — Improper Preservation of Permissions | cvebase