criticalOther

IXON VPN Client Local Privilege Escalation via CRLF Injection (CVE-2026-75925)

First seen Sep 6, 2026 · Updated Sep 6, 2026 · CVSS 9.6

ICSVPNprivilege-escalationCRLF-injectionCWE-93CWE-306remote-code-execution

IXON VPN Client versions before 1.4.7 contain a critical CRLF injection vulnerability that allows an unauthenticated local attacker to inject configuration directives consumed by a privileged subprocess, resulting in remote code execution as root or SYSTEM. The flaw persists silently across restarts with no visible behavioral change, making detection difficult. IXON has released a patched client and blocks connections from vulnerable versions at the cloud/API level as a compensating control.

Technical Analysis

CVE-2026-75925 (CWE-93, contributing CWE-306) affects IXON VPN Client versions prior to 1.4.7. The local configuration service accepts changes without authenticating the requester and writes configuration values to a file consumed by a privileged subprocess without neutralizing CRLF line-ending sequences, enabling an attacker to inject additional directives that execute with root or SYSTEM privileges. The injected malicious configuration persists on disk across client and OS restarts while the VPN connection continues functioning normally, giving attackers a stealthy, durable foothold. CVSS v3.1 score is 9.6 (Critical) via network attack vector requiring low complexity and user interaction; CVSS v4.0 score is 9.4. This vulnerability targets endpoint VPN clients used for remote industrial/OT access rather than AI agent infrastructure directly, but any organization running AI agents or automation tooling on hosts that also use IXON VPN Client for remote access should treat this as a critical local privilege escalation risk, since a compromised host could expose agent credentials, API keys, or orchestration tooling running on the same machine.

Affected Systems

IXON VPN Client versions prior to 1.4.7, deployed on Windows/Linux hosts used for remote access to industrial control systems in Commercial Facilities, Critical Manufacturing, Energy, Information Technology, and Water/Wastewater sectors worldwide.

Indicators of Compromise

  • No public IOCs reported; no known public exploitation observed at time of disclosure.

Remediation Steps

  1. 1

    Update IXON VPN Client

    Upgrade all installations of IXON VPN Client to version 1.4.7 or later immediately.

  2. 2

    Uninstall if unused

    Remove the IXON VPN Client from systems where it is no longer required to reduce attack surface.

  3. 3

    Verify cloud-side enforcement

    Confirm IXON cloud backend rejects connections from clients below v1.4.7, as enforced since August 5, 2026, to prevent completion of the exploit chain on unpatched systems.

  4. 4

    Network segmentation

    Isolate control system networks and remote access devices from business networks and the internet; restrict VPN endpoint exposure.

  5. 5

    Review advisory guidance

    Consult the IXON Trust Center Advisory (ADV-2026-08-05) for detailed mitigation and detection guidance.

CVE / Advisory IDs

CVE-2026-75925

Industries Most Exposed

Commercial FacilitiesCritical ManufacturingEnergyInformation TechnologyWater and Wastewater

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.