Privilege Escalation in OpenVPN Connect on macOS
CVE-2026-9560

8.9HIGH

Key Information:

Vendor
CVE Published:
26 May 2026

What is CVE-2026-9560?

A vulnerability exists in OpenVPN Connect for macOS versions 3.5.1 to 3.8.1, where attackers can exploit a background service to achieve privilege escalation. By leveraging the local IPC channel, attackers may execute arbitrary commands with elevated privileges, potentially compromising the security of the system.

Affected Version(s)

OpenVPN Connect MacOS 3.5.1 <= 3.8.1

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.