OpenVPN Plugin Vulnerability in openvpn-auth-oauth2 for OIDC Authentication by OpenVPN
CVE-2026-41070

10CRITICAL

Key Information:

Vendor

Jkroepke

Vendor
CVE Published:
8 May 2026

What is CVE-2026-41070?

The openvpn-auth-oauth2 plugin for OpenVPN, when deployed in experimental plugin mode, allows clients that lack support for WebAuth and Single Sign-On (SSO) to be improperly admitted to the VPN. This occurs even when the authentication logic denies access, creating a potential security risk. The issue is specific to versions ranging from 1.26.3 to just before 1.27.3 and does not affect the default management-interface mode. The vulnerability has been addressed in version 1.27.3.

Affected Version(s)

openvpn-auth-oauth2 >= 1.26.3, < 1.27.3

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.