CVE-2026-81830

Summary

The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation

Affected Software

VendorProductVersion RangeStatus
OpenVPNOpenVPN2.4.0 <= 2.6.22affected

Weaknesses

  • CWE-73: CWE-73 External control of file name or path

References