Local Configuration Bypass Vulnerability in OpenVPN by OpenVPN Technologies
CVE-2026-63649
4.1MEDIUM
What is CVE-2026-63649?
The Windows interactive service in OpenVPN versions 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 contains a vulnerability that allows local authenticated users to circumvent the trusted configuration directory constraint. By crafting specific options, these users can load arbitrary configuration files, effectively bypassing whitelist checks meant to secure the configuration handling process. This could lead to unauthorized access or manipulation of sensitive configurations, potentially compromising overall system security.
Affected Version(s)
OpenVPN Windows 2.4.0 < 2.6.22
OpenVPN Windows 2.7_alpha1 < 2.7.6