
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-82312 is a denial-of-service vulnerability in OpenVPN for Windows caused by NULL Discretionary Access Control Lists (DACLs) on named Inter-Process Communication (IPC) objects. It affects OpenVPN versions 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows. The vulnerability was published on September 7, 2026, and a patch is available. It carries a CVSS v4.0 base score of 1.8 (Low) (GitHub Advisory, Red Hat Bugzilla).
The root cause is incorrect permission assignment on named IPC objects in OpenVPN's Windows implementation, where a NULL DACL is applied instead of a properly restricted access control list (CWE-412: Unrestricted Externally Accessible Lock; CWE-732: Incorrect Permission Assignment for Critical Resource; CWE-279: Incorrect Execution-Assigned Permissions). A NULL DACL grants unrestricted access to any authenticated local user, allowing them to interact with or disrupt the named IPC objects used by the OpenVPN service. Exploitation requires local authenticated access to the Windows system running a vulnerable OpenVPN version, as well as passive user interaction (e.g., a legitimate user or process must be using the IPC object). No public proof-of-concept code has been identified (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation allows any authenticated local Windows user to crash or disrupt the OpenVPN service, resulting in a denial-of-service condition. There is no impact on confidentiality or integrity of the vulnerable system itself; however, the CVSS v4.0 scoring notes a high availability impact on subsequent systems (e.g., VPN-dependent services or connected clients). Lateral movement or data exfiltration are not directly enabled by this vulnerability (GitHub Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept for CVE-2026-82312. The EPSS score is approximately 0.101%, placing it in the 1st percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment confirms no known exploitation (GitHub Advisory).
OpenVPN has released version 2.7.7 (and a corresponding stable branch fix) addressing this and six other security flaws. Users should upgrade to OpenVPN 2.7.7 or a patched stable release beyond 2.6.22. As interim mitigations, administrators should restrict local user access on systems running OpenVPN and implement access controls to limit which users can interact with IPC objects (GitHub Advisory, OpenVPN Security Announcement).
Security news outlets including CyberSecurityNews and Linuxiac covered the OpenVPN 2.7.7 release, noting it addressed seven security flaws including CVE-2026-82312. Coverage characterized the release as a significant security update for both Windows-specific and cross-platform issues (CyberSecurityNews, Linuxiac).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."