CVE-2026-78043

Summary

The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths

Affected Software

VendorProductVersion RangeStatus
OpenVPNOpenVPN2.7_alpha1 <= 2.7.6affected

Weaknesses

  • CWE-22: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

References