Bypass of Configuration Constraints in OpenVPN by Local Authenticated Users
CVE-2026-78043
5.6MEDIUM
What is CVE-2026-78043?
In OpenVPN versions 2.7_alpha1 through 2.7.6, a security flaw allows local authenticated users to bypass the restrictions on trusted configuration directories. This vulnerability permits the loading of arbitrary configuration files through specially crafted paths, which can potentially lead to unauthorized actions within the application. It highlights the importance of securing local user access and maintaining stringent configuration controls.
Affected Version(s)
OpenVPN Windows 2.7_alpha1 <= 2.7.6