CVE-2026-82312
Received Received - Intake

OpenVPN for Windows Local DoS via NULL DACL

Vulnerability report for CVE-2026-82312, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-07

Last updated on: 2026-09-07

Assigner: OpenVPN Inc.

Description

OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of service via a NULL DACL on named IPC objects

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-07
Last Modified
2026-09-07
Generated
2026-09-07
AI Q&A
2026-09-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
openvpn openvpn From 2.0.0 (inc) to 2.6.22 (inc)
openvpn openvpn From 2.7_alpha1 (inc) to 2.7.6 (inc)
openvpn openvpn From 2.7.0 (inc) to 2.7.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-732 The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
CWE-412 The product properly checks for the existence of a lock, but the lock can be externally controlled or influenced by an actor that is outside of the intended sphere of control.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects OpenVPN versions 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows. It allows a local authenticated user to cause a denial of service by setting a NULL Discretionary Access Control List (DACL) on named Inter-Process Communication (IPC) objects.

Detection Guidance

This vulnerability involves a NULL DACL on named IPC objects in OpenVPN on Windows, which could allow local authenticated users to cause a denial of service. Detection requires checking for NULL DACLs on OpenVPN IPC objects. Use tools like icacls or PowerShell to inspect DACLs on named objects in the OpenVPN directory or registry. No specific commands are provided in the context.

Impact Analysis

An attacker with local authenticated access could exploit this to crash the OpenVPN service, disrupting VPN connections and potentially causing service outages for other users.

Compliance Impact

The vulnerability allows local authenticated users to cause a denial of service via a NULL DACL on named IPC objects in OpenVPN versions 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows. This could potentially impact compliance by disrupting service availability, which may violate availability requirements in standards like GDPR or HIPAA.

Mitigation Strategies

Update OpenVPN to a version beyond 2.6.22 or 2.7.6 to address the NULL DACL issue on named IPC objects. Verify the update by checking the installed version with 'openvpn --version'.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82312. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart