CVE-2026-82312
1.8
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:H
Summary
OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of service via a NULL DACL on named IPC objects
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OpenVPN | OpenVPN | 2.0.0 <= 2.6.22 | affected |
| OpenVPN | OpenVPN | 2.7_alpha1 <= 2.7.6 | affected |
Weaknesses
- CWE-732: CWE-732 Incorrect Permission Assignment for Critical Resource
- CWE-412: CWE-412 Unrestricted externally accessible lock
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.