CVE-2026-63650

Summary

OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field

Affected Software

VendorProductVersion RangeStatus
OpenVPNOpenVPN2.7_alpha1 < 2.7.6affected

Weaknesses

  • CWE-295: CWE-295 Improper Certificate Validation
  • CWE-115: CWE-115 Misinterpretation of Input

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References