File Path Validation Flaw in OpenVPN Affects Windows Interactive Service
CVE-2026-81830

5.6MEDIUM

Key Information:

Vendor

Openvpn

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-81830?

A vulnerability in the Windows interactive service of OpenVPN versions 2.4.0 to 2.6.22 allows local authenticated users to potentially bypass crucial trusted configuration directory constraints due to improper file path validation. This flaw can lead to unauthorized access or manipulation, emphasizing the need for timely updates and security patches to safeguard system integrity. Users are advised to review the security advisories and apply necessary fixes as they become available.

Affected Version(s)

OpenVPN Windows 2.4.0 <= 2.6.22

References

CVSS V4

Score:
5.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.