CVE-2026-84226

Summary

OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps

Affected Software

VendorProductVersion RangeStatus
OpenVPNOpenVPN2.5.0 <= 2.6.22affected
OpenVPNOpenVPN2.7_alpha1 <= 2.7.6affected

Weaknesses

  • CWE-426: CWE-426 Untrusted Search Path

References