CVE-2026-63650: Openvpn

Low severity, CVSS 2.0. EPSS: 0.4% chance of exploitation in the next 30 days.

OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field

Affected products

  • Openvpn Openvpn: from 2.7_alpha1, before 2.7.6 (fixed in 2.7.6)

Published 2026-08-14. Last modified 2026-09-01.