Argument Parsing Issue in OpenVPN Affects Windows Users
CVE-2026-84256

7.7HIGH

Key Information:

Vendor

Openvpn

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-84256?

A security flaw in OpenVPN versions 2.1_rc10 up to 2.6.22, and 2.7_alpha1 through 2.7.6 on Windows platforms, allows authenticated remote users to execute arbitrary commands by exploiting a vulnerability in the argument parsing mechanism when a specially crafted certificate subject is presented. This weakness poses a risk to system integrity and highlights the need for timely patching.

Affected Version(s)

OpenVPN Windows 2.1_rc10 <= 2.6.22

OpenVPN Windows 2.7_alpha1 <= 2.7.6

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.