CVE-2026-82312

Summary

OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of service via a NULL DACL on named IPC objects

Affected Software

VendorProductVersion RangeStatus
OpenVPNOpenVPN2.0.0 <= 2.6.22affected
OpenVPNOpenVPN2.7_alpha1 <= 2.7.6affected

Weaknesses

  • CWE-732: CWE-732 Incorrect Permission Assignment for Critical Resource
  • CWE-412: CWE-412 Unrestricted externally accessible lock

References