The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 07 Sep 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation | |
| Weaknesses | CWE-73 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: OpenVPN
Published:
Updated: 2026-09-07T07:36:19.096Z
Reserved: 2026-08-27T14:00:41.210Z
Link: CVE-2026-81830
No data.
Status : Received
Published: 2026-09-07T08:17:13.410
Modified: 2026-09-07T08:17:13.410
Link: CVE-2026-81830
No data.
OpenCVE Enrichment
No data.
Weaknesses