CVE-2026-81830
5.6
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
Summary
The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OpenVPN | OpenVPN | 2.4.0 <= 2.6.22 | affected |
Weaknesses
- CWE-73: CWE-73 External control of file name or path
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.