CVE-2026-11771
Awaiting Analysis Awaiting Analysis - Queue

OpenVPN NTLM Proxy Authentication Off-by-One Buffer Write

Vulnerability report for CVE-2026-11771, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: OpenVPN Inc.

Description

OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
openvpn openvpn From 2.1.0 (inc) to 2.6.20 (inc)
openvpn openvpn From 2.7_alpha1 (inc) to 2.7.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CWE-193 A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an off-by-one buffer write flaw in OpenVPN versions 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4. It occurs during NTLM proxy authentication when processing a crafted NTLM response from a malicious proxy server, potentially causing a crash.

Detection Guidance

This vulnerability can be detected by checking the OpenVPN version installed on your system. Run 'openvpn --version' to verify if your version is between 2.1.0 and 2.6.20 or 2.7_alpha1 and 2.7.4. If so, the system is vulnerable.

Impact Analysis

An attacker could exploit this to crash OpenVPN, leading to denial of service. If OpenVPN is used for secure remote access, this could disrupt network connectivity or VPN services.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it involves a potential crash due to an off-by-one buffer write in NTLM proxy authentication. No evidence suggests data breaches or unauthorized access, which are key concerns for these regulations.

Mitigation Strategies

Immediately update OpenVPN to a version later than 2.6.20 or 2.7.4. Disable NTLM proxy authentication if not required. Monitor network traffic for suspicious NTLM responses from proxy servers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11771. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart