
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-63650 is an authentication misidentification vulnerability in OpenVPN affecting versions 2.7_alpha1 through 2.7.5 when using the mbedTLS cryptographic backend. The flaw causes the configured X.509 username identity lookup field to be ignored during authentication, allowing remote authenticated users to be misidentified. It was published on August 14, 2026, with a patch released in OpenVPN 2.7.6. The vulnerability carries a CVSS v4.0 base score of 2.0 (Low) (GitHub Advisory, ENISA EUVD).
The root cause is classified under CWE-115 (Misinterpretation of Input) and CWE-295 (Improper Certificate Validation). When OpenVPN is configured to use mbedTLS and a specific X.509 field (e.g., CN, SAN, or email) for username identity lookup, the implementation fails to correctly apply this configuration, effectively ignoring the designated field during certificate-based authentication. This means the identity derived from the certificate does not match the intended configured field, leading to user misidentification. Exploitation requires the attacker to already be an authenticated user with a valid certificate, and additional preconditions (attack requirements marked as "Present") must be met, making exploitation non-trivial (GitHub Advisory, ENISA EUVD).
Successful exploitation allows an authenticated attacker to be misidentified as a different user during VPN session establishment, potentially gaining access to network resources or permissions associated with another user's identity. The confidentiality impact is limited — both the vulnerable system and subsequent systems show low confidentiality impact with no integrity or availability impact per the CVSS v4.0 assessment. There is no evidence of data destruction or service disruption risk, but the identity confusion could enable unauthorized access to network segments or resources scoped to the impersonated user (GitHub Advisory, ENISA EUVD).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.364% (30th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an attacker to already possess valid credentials and a legitimate certificate, significantly limiting the attack surface (GitHub Advisory, ENISA EUVD).
OpenVPN released version 2.7.6 on August 5, 2026, which addresses this vulnerability. All users running OpenVPN 2.7_alpha1 through 2.7.5 with the mbedTLS backend should upgrade to 2.7.6 or later immediately. As a temporary workaround until patching is feasible, administrators should enforce strict X.509 certificate validation at the network perimeter and review VPN access logs for anomalous identity assignments. Note that this vulnerability only affects deployments using mbedTLS; configurations using OpenSSL are not affected (OpenVPN Release History, OpenVPN Security Advisory).
Coverage has been limited to vulnerability tracking platforms and self-hosted software community blogs. A self-hosted weekly digest noted the release of OpenVPN 2.7.6 with security fixes in the context of broader open-source security updates (Linuxiac). No significant researcher commentary or major media coverage has been identified for this low-severity vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."