Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-82325
OpenVPN vulnerability analysis and mitigation

Overview

CVE-2026-82325 is a use-after-free (and double-free) vulnerability in the OpenVPN ovpn-dco-win Windows kernel driver that allows local authenticated users to cause a system crash via crafted control messages. It affects driver versions 2.5.0 through 2.8.6, with versions prior to 2.5.0 and after 2.8.6 listed as unaffected. The vulnerability was published on September 7, 2026, and carries a CVSS v4.0 base score of 6.8 (Medium) (GitHub Advisory, ENISA EUVD).

Technical details

The root cause is classified as CWE-416 (Use After Free) and CWE-415 (Double Free), meaning the driver incorrectly manages memory references for kernel objects after they have been freed, potentially allowing a second free operation on the same memory address. An attacker with local authenticated access can send specially crafted control messages to the ovpn-dco-win driver, triggering the improper memory handling and causing a kernel crash (Blue Screen of Death / BSOD). The attack requires low privileges, no user interaction, and no special attack conditions beyond local access (GitHub Advisory, ENISA EUVD).

Impact

Successful exploitation results in a system crash (denial of service), causing unexpected reboots and disruption of all services running on the affected Windows host. There is no assessed impact to confidentiality or integrity — the vulnerability is limited to availability of the vulnerable system. Subsequent systems are not impacted, and no lateral movement or data exfiltration capability has been identified (GitHub Advisory, ENISA EUVD).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of active in-the-wild exploitation as of the time of publication. The EPSS score is approximately 0.099% (1st percentile), indicating a low probability of exploitation in the near term. The NVD SSVC assessment classifies exploitation as "none" and the vulnerability as non-automatable. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, ENISA EUVD).

Mitigation and workarounds

Update the OpenVPN ovpn-dco-win driver to a version newer than 2.8.6, which contains the fix for this vulnerability. As a compensating control, restrict local system access to trusted and authorized users only to reduce the attack surface. Monitor for unexplained system crashes or BSODs referencing the OpenVPN driver and investigate any unexpected reboots on systems running the affected driver versions (GitHub Advisory, OpenVPN Advisory).

Additional resources


SourceThis report was generated using AI

Related OpenVPN vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84732HIGH8.7
  • OpenVPN logoOpenVPN
  • cpe:2.3:a:openvpn:openvpn
NoYesSep 07, 2026
CVE-2026-84226HIGH8.5
  • OpenVPN logoOpenVPN
  • cpe:2.3:a:openvpn:openvpn
NoYesSep 07, 2026
CVE-2026-84256HIGH7.7
  • OpenVPN logoOpenVPN
  • cpe:2.3:a:openvpn:openvpn
NoYesSep 07, 2026
CVE-2026-82325MEDIUM6.8
  • OpenVPN logoOpenVPN
  • openvpn
NoNoSep 07, 2026
CVE-2026-82312LOW1.8
  • OpenVPN logoOpenVPN
  • cpe:2.3:a:openvpn:openvpn
NoYesSep 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management