Authentication Bypass Vulnerability in OpenVPN by OpenVPN Technologies
CVE-2026-63650
2LOW
What is CVE-2026-63650?
This vulnerability in OpenVPN versions 2.7_alpha1 to 2.7.5 involves an authentication bypass due to misconfiguration in the mbedTLS library. When using X.509 certificates, remote authenticated users may be incorrectly identified, allowing unauthorized access. It is essential for users of affected versions to review their configuration settings and apply any available patches to mitigate potential risks.
Affected Version(s)
OpenVPN 2.7_alpha1 < 2.7.6