CVE-2026-63650
2
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Summary
OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OpenVPN | OpenVPN | 2.7_alpha1 < 2.7.6 | affected |
Weaknesses
- CWE-295: CWE-295 Improper Certificate Validation
- CWE-115: CWE-115 Misinterpretation of Input
References
- https://community.openvpn.net/Security%20Announcements/CVE-2026-63650
- https://community.openvpn.net/ReleaseHistory#openvpn-276-released-5-august-2026
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.