4.1
CVE-2026-63649
- EPSS 0.33%
- Veröffentlicht 14.08.2026 22:13:21
- Zuletzt bearbeitet 17.08.2026 16:17:21
- CVE-Watchlists
- Unerledigt
The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that bypass whitelist checks
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerOpenVPN
≫
Produkt
OpenVPN
Default Statusunaffected
Version
2.4.0
Version <
2.6.22
Status
affected
Version
2.7_alpha1
Version <
2.7.6
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.258 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@openvpn.net | 4.1 | 0 | 0 |
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-183 Permissive List of Allowed Inputs
The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are explicitly allowed by policy because the inputs are assumed to be safe, but the list is too permissive - that is, it allows an input that is unsafe, leading to resultant weaknesses.
https://community.openvpn.net/Security%20Announcements/CVE-2026-63649
https://community.openvpn.net/ReleaseHistory#openvpn-276-released-5-august-2026
https://community.openvpn.net/ReleaseHistory#openvpn-2622-released-5-august-2026