CVE-2026-63649: Openvpn

Medium severity, CVSS 4.1. EPSS: 0.3% chance of exploitation in the next 30 days.

The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that bypass whitelist checks

Affected products

  • Openvpn Openvpn: from 2.4.0, before 2.6.22 (fixed in 2.6.22); from 2.7_alpha1, before 2.7.6 (fixed in 2.7.6)

Published 2026-08-14. Last modified 2026-09-01.