CVE-2026-63649
MEDIUM
4,1
Source: [email protected]
Attack Vector: local
Attack Complexity: low
Privileges Required: low
User Interaction: active
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that bypass whitelist checks
183
Permissive List of Allowed Inputs
DraftCommon Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism
Applicable Platforms
All platforms may be affected
https://community.openvpn.net/ReleaseHistory#openvpn-2622-released-5-august-2026
https://community.openvpn.net/ReleaseHistory#openvpn-276-released-5-august-2026
https://community.openvpn.net/Security%20Announcements/CVE-2026-63649