CVE-2026-63649
Received Received - Intake

Windows Interactive Service Configuration Bypass in OpenVPN

Vulnerability report for CVE-2026-63649, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-14

Last updated on: 2026-08-14

Assigner: OpenVPN Inc.

Description

The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that bypass whitelist checks

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-14
Last Modified
2026-08-14
Generated
2026-08-15
AI Q&A
2026-08-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
openvpn openvpn From 2.4.0 (inc) to 2.6.21 (inc)
openvpn openvpn From 2.7_alpha1 (inc) to 2.7.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-183 The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are explicitly allowed by policy because the inputs are assumed to be safe, but the list is too permissive - that is, it allows an input that is unsafe, leading to resultant weaknesses.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects OpenVPN versions 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5. It allows local authenticated users to bypass security checks in the Windows interactive service and load arbitrary configuration files by exploiting crafted options that bypass whitelist restrictions.

Detection Guidance

This vulnerability involves the Windows interactive service in OpenVPN versions 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5. To detect it, check the OpenVPN version installed on your system using 'openvpn --version'. If the version falls within the affected range, the system is vulnerable.

Impact Analysis

An attacker with local authenticated access could exploit this to load malicious configuration files, potentially gaining elevated privileges or executing unauthorized actions on the system. This could lead to unauthorized network access or data breaches.

Compliance Impact

This vulnerability could lead to unauthorized access or data exposure, which may violate compliance requirements such as GDPR (data protection) or HIPAA (health information security). Organizations using affected OpenVPN versions may face regulatory penalties or reputational damage.

Mitigation Strategies

Update OpenVPN to a version beyond 2.6.21 or 2.7.5 where the issue is resolved. If immediate update is not possible, restrict local user access to configuration files and review whitelist checks for configuration directory constraints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63649. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart