CVE-2026-81830: Openvpn

Medium severity, CVSS 5.6. EPSS: 0.2% chance of exploitation in the next 30 days.

The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation

Affected products

  • Openvpn Openvpn: from 2.4.0, up to and including 2.6.22

Published 2026-09-07. Last modified 2026-09-08.