CVE-2026-63649

Published: Ago 15, 2026 Last Modified: Ago 15, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 4,1
Attack Vector: local
Attack Complexity: low
Privileges Required: low
User Interaction: active
Confidentiality: N/A
Integrity: N/A
Availability: N/A

Description

AI Translation Available

The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that bypass whitelist checks

183

Permissive List of Allowed Inputs

Draft
Common Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism
Applicable Platforms
All platforms may be affected
View CWE Details
https://community.openvpn.net/ReleaseHistory#openvpn-2622-released-5-august-2026
https://community.openvpn.net/ReleaseHistory#openvpn-276-released-5-august-2026
https://community.openvpn.net/Security%20Announcements/CVE-2026-63649