CVE-2026-13379
OpenVPN vulnerability analysis and mitigation

Overview

CVE-2026-13379 is a vulnerability in the Windows interactive service of OpenVPN that allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process. It affects OpenVPN versions 2.7_alpha1 through 2.7.4 on Windows. The vulnerability was published on July 30, 2026, with a patch available in OpenVPN 2.7.5. It carries a CVSS v3.1 base score of 9.1 (Critical) and a CVSS v4.0 base score of 5.1 (Medium) (GitHub Advisory, OpenVPN Advisory).

Technical details

The root cause is classified as CWE-125 (Out-of-bounds Read) and CWE-142 (Improper Neutralization of Value Delimiters), indicating that the Windows interactive service fails to properly validate or sanitize search domain values received during the VPN disconnection process (GitHub Advisory). An attacker can send a specially crafted search domain string that triggers either an out-of-bounds read leading to a service crash, or causes the service to persist malicious DNS configuration state on the host system. The attack vector is network-based and requires no authentication (CVSS v3.1), though the CVSS v4.0 assessment notes attack requirements are present and some level of privileges and passive user interaction may be involved depending on deployment context.

Impact

Successful exploitation can result in two distinct outcomes: a crash of the OpenVPN Windows interactive service (denial of service), or persistent DNS state pollution on the affected Windows host. DNS state pollution is particularly concerning as it can redirect network traffic to attacker-controlled infrastructure, potentially enabling man-in-the-middle attacks or facilitating further compromise of the affected system and connected network resources. The subsequent system confidentiality and availability impacts are rated High under CVSS v4.0, reflecting the potential for significant downstream effects beyond the OpenVPN service itself (GitHub Advisory, OpenVPN Advisory).

Exploitability

As of the time of publication, there is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.286–0.338%, placing it in roughly the 27th percentile for exploitation probability within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. NVD's SSVC assessment classifies exploitation as "none" at this time, with technical impact rated as "partial" and the vulnerability noted as not automatable.

Exploitation steps

  1. Reconnaissance: Identify Windows hosts running OpenVPN versions 2.7_alpha1 through 2.7.4 using network scanning tools (e.g., Shodan, Censys, or Nmap with service fingerprinting).
  2. Position for interaction: Establish a network position capable of interacting with the OpenVPN Windows interactive service, which may require some level of network access to the target.
  3. Craft malicious search domain: Construct a specially crafted search domain string designed to trigger an out-of-bounds read or improper value delimiter handling in the Windows interactive service.
  4. Trigger during disconnection: Send or inject the crafted search domain value during the VPN disconnection process, when the service processes DNS configuration cleanup.
  5. Achieve objective: Depending on the payload, either crash the OpenVPN service (denial of service) or cause the service to write malicious DNS search domain entries that persist on the Windows host, potentially redirecting DNS resolution for subsequent connections (GitHub Advisory, OpenVPN Advisory).

Indicators of compromise

  • Logs: Unexpected crashes or restarts of the OpenVPN interactive service (openvpnserv.exe) recorded in Windows Event Logs (Application/System logs); error entries related to DNS configuration during VPN disconnection events.
  • Network: Anomalous DNS search domain entries appearing in Windows network adapter configuration after VPN disconnection; unexpected DNS queries being directed to unfamiliar resolvers.
  • File System / Registry: Unexpected or persistent DNS suffix search list entries in the Windows registry under HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\SearchList or per-adapter DNS settings that do not match expected VPN configuration.
  • Process: Abnormal termination of openvpnserv.exe or repeated service restarts visible in Windows Service Control Manager logs.

Mitigation and workarounds

The primary remediation is to upgrade OpenVPN to version 2.7.5 or later, which was released on July 1, 2026, and addresses this vulnerability (OpenVPN Release History, OpenVPN Advisory). If immediate patching is not feasible, administrators should monitor OpenVPN services for unexpected crashes, verify DNS settings are not being altered by untrusted sources, and restrict network access to OpenVPN services where possible. SUSE has also issued a security update (SUSE-SU-2026:3596-1) for affected Linux packages, though the Windows interactive service is the primary attack surface (SUSE Advisory).

Community reactions

SUSE issued a security update (SUSE-SU-2026:3596-1) addressing this and related OpenVPN vulnerabilities, indicating broad ecosystem response (SUSE Advisory). Tenable added detection coverage via Nessus plugins (IDs 331394 and 335070) and Qualys also added detection (ID 764544), reflecting standard scanner vendor response to the disclosure. No significant independent researcher commentary or notable social media discussion has been identified beyond routine CVE tracking and aggregation sites.

Additional resources


SourceThis report was generated using AI

Related OpenVPN vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13117MEDIUM6
  • OpenVPN logoOpenVPN
  • openvpn-auth-pam-plugin
NoYesJul 30, 2026
CVE-2026-12996MEDIUM6
  • OpenVPN logoOpenVPN
  • cpe:2.3:a:openvpn:openvpn
NoYesJul 30, 2026
CVE-2026-13379MEDIUM5.1
  • OpenVPN logoOpenVPN
  • openvpn-dco-devel
NoYesJul 30, 2026
CVE-2026-63649MEDIUM4.1
  • OpenVPN logoOpenVPN
  • cpe:2.3:a:openvpn:openvpn
NoYesAug 14, 2026
CVE-2026-63650LOW2
  • OpenVPN logoOpenVPN
  • openvpn
NoNoAug 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management