Local Configuration Bypass Vulnerability in OpenVPN by OpenVPN Technologies
CVE-2026-63649

4.1MEDIUM

Key Information:

Vendor

Openvpn

Status
Vendor
CVE Published:
14 August 2026

What is CVE-2026-63649?

The Windows interactive service in OpenVPN versions 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 contains a vulnerability that allows local authenticated users to circumvent the trusted configuration directory constraint. By crafting specific options, these users can load arbitrary configuration files, effectively bypassing whitelist checks meant to secure the configuration handling process. This could lead to unauthorized access or manipulation of sensitive configurations, potentially compromising overall system security.

Affected Version(s)

OpenVPN Windows 2.4.0 < 2.6.22

OpenVPN Windows 2.7_alpha1 < 2.7.6

References

CVSS V4

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.