CVE-2026-63649: Openvpn
Medium severity, CVSS 4.1. EPSS: 0.3% chance of exploitation in the next 30 days.
The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that bypass whitelist checks
Affected products
- Openvpn Openvpn: from 2.4.0, before 2.6.22 (fixed in 2.6.22); from 2.7_alpha1, before 2.7.6 (fixed in 2.7.6)
Published 2026-08-14. Last modified 2026-09-01.