CVE-2026-78043: Openvpn
Medium severity, CVSS 5.6. EPSS: 0.2% chance of exploitation in the next 30 days.
The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths
Affected products
- Openvpn Openvpn: from 2.7_alpha1, up to and including 2.7.6
Published 2026-09-07. Last modified 2026-09-08.