
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-63649 is an authorization bypass vulnerability in the Windows interactive service of OpenVPN that allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that circumvent whitelist checks. It affects OpenVPN versions 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 on Windows. The vulnerability was published on August 14, 2026, with patches released in OpenVPN 2.6.22 and 2.7.6. It carries a CVSS v4.0 base score of 4.1 (Medium) (GitHub Advisory, Red Hat Bugzilla).
The root cause is classified under CWE-183 (Permissive List of Allowed Inputs) and CWE-22 (Path Traversal), where the Windows interactive service's whitelist validation logic is insufficiently strict, allowing crafted input options to escape the trusted configuration directory boundary. An attacker with local authenticated access can supply specially crafted configuration options — potentially using encoding tricks or path manipulation techniques (consistent with CAPEC-126 Path Traversal and CAPEC-120 Double Encoding) — to cause the service to load configuration files from outside the approved directory. Exploitation requires low privileges and active user interaction, limiting the attack surface to local users on Windows systems running the OpenVPN interactive service (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation allows a local authenticated user to load arbitrary VPN configuration files outside the trusted directory, potentially enabling execution of malicious VPN configurations, access to unauthorized network resources, or privilege escalation — as noted in Red Hat's bug tracker summary ('Privilege escalation via arbitrary configuration file loading'). The subsequent system confidentiality impact is rated High in CVSS v4.0, indicating that sensitive information accessible through manipulated VPN configurations could be exposed. Integrity and availability of the vulnerable system itself are not directly impacted, but lateral movement to otherwise inaccessible network segments via rogue VPN configurations is a realistic concern (GitHub Advisory, Red Hat Bugzilla).
There is currently no public proof-of-concept exploit code and no evidence of in-the-wild exploitation for CVE-2026-63649. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.33% (26th percentile), indicating a low near-term exploitation probability. NVD's SSVC assessment also classifies exploitation as 'none' at this time (GitHub Advisory).
..\, URL encoding, or double encoding) designed to bypass the whitelist validation logic in the interactive service.openvpnserv.exe) accessing unusual file paths..ovpn configuration files in non-standard directories; recently created or modified configuration files in user-writable locations that reference external or attacker-controlled VPN endpoints.openvpnserv.exe spawning connections to unexpected remote endpoints not matching known VPN server addresses; unusual network interface creation or routing table changes following OpenVPN service activity.OpenVPN has released patched versions 2.6.22 and 2.7.6 (both released August 5, 2026) that address this vulnerability. Users should upgrade to one of these versions immediately. As interim mitigations, administrators should restrict local user access to systems running the OpenVPN interactive service, apply the principle of least privilege for accounts interacting with OpenVPN services, and ensure the trusted configuration directory has strict access controls preventing unauthorized writes (GitHub Advisory, Red Hat Bugzilla).
Coverage of CVE-2026-63649 has been limited to standard vulnerability tracking and aggregation platforms. Linuxiac covered the OpenVPN 2.7.6 release noting the security fixes for Windows. Red Hat has tracked the issue via Bugzilla with a 'high' severity rating. No notable independent researcher commentary or significant social media discussion has been observed beyond routine CVE publication and aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."