CVE-2026-11771
OpenVPN vulnerability analysis and mitigation

Overview

CVE-2026-11771 is a Denial of Service vulnerability in OpenVPN caused by an off-by-one buffer write in the NTLM proxy authentication code. A malicious proxy server can send a crafted NTLM response to trigger a crash in the OpenVPN client. Affected versions include OpenVPN 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4. The vulnerability was published on July 30, 2026, with patches released on July 1, 2026 (versions 2.6.21 and 2.7.5). It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 7.0 (High) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is an off-by-one error (CWE-193) leading to a stack-based buffer overflow (CWE-121) and out-of-bounds write (CWE-787) in the NTLM proxy authentication handling code. When an OpenVPN client connects through an HTTP proxy using NTLM authentication, a malicious proxy server can return a specially crafted NTLM response that triggers the off-by-one write, corrupting stack memory and causing a process crash. Exploitation requires the attacker to control or impersonate the proxy server that the OpenVPN client is configured to use, and the client must have NTLM proxy authentication enabled — meaning passive user interaction (initiating a VPN connection) is a prerequisite (GitHub Advisory, Red Hat Bugzilla).

Impact

Successful exploitation results in a crash of the OpenVPN client process, causing a Denial of Service that disrupts VPN connectivity for the affected user. There is no impact on confidentiality or integrity — the vulnerability is limited to availability. Because the crash affects only the client process, lateral movement or data exfiltration are not direct consequences of this vulnerability, though loss of VPN connectivity could expose users to less secure network paths (GitHub Advisory, Red Hat Bugzilla).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable. The EPSS score is approximately 0.34–0.375%, placing it in roughly the 30th percentile for exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Setup a malicious proxy server: The attacker deploys or compromises an HTTP proxy server that supports NTLM authentication and is positioned to intercept OpenVPN client connections (e.g., via network interception, DNS spoofing, or ARP poisoning on a local network).
  2. Redirect the OpenVPN client: The attacker ensures the target OpenVPN client is configured to route through the malicious proxy, either by compromising proxy configuration settings or by performing a man-in-the-middle attack on the network path.
  3. Initiate NTLM authentication: When the OpenVPN client connects and initiates NTLM proxy authentication, the malicious proxy participates in the NTLM handshake.
  4. Send crafted NTLM response: The attacker's proxy returns a specially crafted NTLM response message designed to trigger the off-by-one boundary condition in OpenVPN's NTLM parsing code.
  5. Trigger crash: The malformed response causes an off-by-one write beyond the allocated stack buffer, corrupting adjacent memory and crashing the OpenVPN client process, resulting in loss of VPN connectivity (GitHub Advisory, Red Hat Bugzilla).

Indicators of compromise

  • Process: Unexpected termination or crash of the OpenVPN client process (openvpn) during proxy authentication phase.
  • Logs: OpenVPN log entries showing NTLM proxy authentication attempts followed by abrupt process exit or segmentation fault; crash dump files generated by the OS in /var/crash/ or equivalent.
  • Network: Unusual or unexpected NTLM authentication traffic from a proxy server that does not match the organization's known proxy infrastructure; repeated failed VPN connection attempts through a proxy.
  • System: Core dump files associated with the openvpn process; application event log entries (Windows) indicating OpenVPN process crash during connection establishment.

Mitigation and workarounds

OpenVPN has released patched versions 2.6.21 and 2.7.5, both made available on July 1, 2026, prior to the CVE's public disclosure on July 30, 2026. Users should upgrade to these versions or later immediately. As a workaround, avoid configuring OpenVPN to connect through untrusted or unverified proxy servers, and restrict NTLM proxy authentication to trusted proxy infrastructure only via network controls. Linux distribution packages (Debian, Ubuntu USN-8540-1, SUSE SUSE-SU-2026:3596-1, Amazon Linux 2023 ALAS2023-2026-1990) have also been updated (GitHub Advisory, Red Hat Bugzilla).

Community reactions

Red Hat tracked the vulnerability as medium severity in their Bugzilla system, and multiple Linux distributions including Ubuntu, SUSE, Debian, and Amazon Linux issued security advisories and updated packages promptly after the CVE's publication. The vulnerability received routine coverage from security advisory aggregators such as Linux Security and LinuxCompatible, with no notable controversy or significant social media discussion observed. The security community response has been measured, consistent with the limited exploitation potential and availability-only impact of the flaw.

Additional resources


SourceThis report was generated using AI

Related OpenVPN vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13117MEDIUM6
  • OpenVPN logoOpenVPN
  • openvpn-auth-pam-plugin
NoYesJul 30, 2026
CVE-2026-12996MEDIUM6
  • OpenVPN logoOpenVPN
  • cpe:2.3:a:openvpn:openvpn
NoYesJul 30, 2026
CVE-2026-13379MEDIUM5.1
  • OpenVPN logoOpenVPN
  • openvpn-dco-devel
NoYesJul 30, 2026
CVE-2026-63649MEDIUM4.1
  • OpenVPN logoOpenVPN
  • cpe:2.3:a:openvpn:openvpn
NoYesAug 14, 2026
CVE-2026-63650LOW2
  • OpenVPN logoOpenVPN
  • openvpn
NoNoAug 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management