OpenVPN Plugin Vulnerability in openvpn-auth-oauth2 for OIDC Authentication by OpenVPN
CVE-2026-41070
10CRITICAL
What is CVE-2026-41070?
The openvpn-auth-oauth2 plugin for OpenVPN, when deployed in experimental plugin mode, allows clients that lack support for WebAuth and Single Sign-On (SSO) to be improperly admitted to the VPN. This occurs even when the authentication logic denies access, creating a potential security risk. The issue is specific to versions ranging from 1.26.3 to just before 1.27.3 and does not affect the default management-interface mode. The vulnerability has been addressed in version 1.27.3.
Affected Version(s)
openvpn-auth-oauth2 >= 1.26.3, < 1.27.3
