CVE-2026-84256

Summary

An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject

Affected Software

VendorProductVersion RangeStatus
OpenVPNOpenVPN2.1_rc10 <= 2.6.22affected
OpenVPNOpenVPN2.7_alpha1 <= 2.7.6affected

Weaknesses

  • CWE-78: CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')
  • CWE-88: CWE-88 Improper neutralization of argument delimiters in a command ('argument injection')

References