CVE-2026-78043: Openvpn

Medium severity, CVSS 5.6. EPSS: 0.2% chance of exploitation in the next 30 days.

The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths

Affected products

  • Openvpn Openvpn: from 2.7_alpha1, up to and including 2.7.6

Published 2026-09-07. Last modified 2026-09-08.