Bypass of Configuration Constraints in OpenVPN by Local Authenticated Users
CVE-2026-78043

5.6MEDIUM

Key Information:

Vendor

Openvpn

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-78043?

In OpenVPN versions 2.7_alpha1 through 2.7.6, a security flaw allows local authenticated users to bypass the restrictions on trusted configuration directories. This vulnerability permits the loading of arbitrary configuration files through specially crafted paths, which can potentially lead to unauthorized actions within the application. It highlights the importance of securing local user access and maintaining stringent configuration controls.

Affected Version(s)

OpenVPN Windows 2.7_alpha1 <= 2.7.6

References

CVSS V4

Score:
5.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.