Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-84226
OpenVPN vulnerability analysis and mitigation

Overview

CVE-2026-84226 is a binary planting (untrusted search path) vulnerability in OpenVPN for Windows that allows local authenticated users to execute arbitrary code with elevated privileges during network configuration steps. It affects OpenVPN versions 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows. The vulnerability was published on September 7, 2026, and carries a CVSS v4.0 base score of 8.5 (High) (GitHub Advisory, ENISA EUVD).

Technical details

The vulnerability is classified as CWE-426 (Untrusted Search Path), where OpenVPN on Windows searches for critical binaries or resources using a path that can be manipulated by a local user (GitHub Advisory). During network configuration steps — such as when OpenVPN invokes helper executables or scripts — an attacker can plant a malicious binary in a directory that OpenVPN searches before the legitimate binary location, causing the malicious binary to be executed instead. This technique maps to MITRE ATT&CK T1574.007 (Path Interception by PATH Environment Variable) and CAPEC-38 (Leveraging/Manipulating Configuration File Search Paths). Exploitation requires only low-level local authentication and no user interaction, making it straightforward for any authenticated Windows user on the affected system (ENISA EUVD).

Impact

Successful exploitation allows a local authenticated attacker to achieve arbitrary code execution with elevated privileges on the affected Windows system, resulting in high confidentiality, integrity, and availability impact to the vulnerable system (GitHub Advisory). An attacker could use this privilege escalation as a stepping stone for lateral movement, credential harvesting, or persistent access within the environment. The vulnerability does not affect subsequent/downstream systems directly, but the elevated access gained on the OpenVPN host could expose sensitive VPN credentials and network configuration data (ENISA EUVD).

Exploitability

As of the time of publication, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (ENISA EUVD). The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD SSVC assessment confirms exploitation status as "none" and automatable as "no" (GitHub Advisory). The EPSS score is approximately 0.142% (4th percentile), indicating a low near-term probability of exploitation. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify a Windows system running OpenVPN versions 2.5.0–2.6.22 or 2.7_alpha1–2.7.6 where the attacker has local authenticated access.
  2. Identify vulnerable search path: Determine which directories OpenVPN searches during network configuration steps (e.g., directories in the system PATH, OpenVPN installation directory, or temporary directories writable by low-privileged users).
  3. Plant malicious binary: Place a crafted executable with the same name as a legitimate binary or helper tool that OpenVPN invokes during network configuration (e.g., a network setup helper) into a directory that appears earlier in the search path than the legitimate binary location.
  4. Trigger network configuration: Initiate or wait for an OpenVPN network configuration event (e.g., connecting/disconnecting a VPN tunnel, restarting the OpenVPN service) that causes OpenVPN to search for and execute the helper binary.
  5. Achieve privilege escalation: The malicious binary is executed in place of the legitimate one, potentially running with the elevated privileges of the OpenVPN service or process, granting the attacker arbitrary code execution at a higher privilege level (GitHub Advisory, ENISA EUVD).

Indicators of compromise

  • File System: Unexpected executables placed in directories included in the system PATH or OpenVPN installation/working directories, particularly files matching names of known OpenVPN helper binaries or network configuration tools; recently modified or newly created .exe files in user-writable directories on the PATH.
  • Process: Unusual child processes spawned by the OpenVPN process (openvpn.exe) or its service, especially processes not matching expected OpenVPN helper binaries; processes running with elevated privileges originating from user-writable directories.
  • Logs: Windows Event Logs (Security, System) showing process creation events (Event ID 4688) where the executable path for OpenVPN helper processes points to unexpected or user-writable directories; Windows Defender or AV alerts related to binary planting or suspicious executable loading during VPN connection events.
  • Network: Unexpected outbound connections from the OpenVPN host to unknown external IPs following VPN connection/disconnection events, which may indicate post-exploitation activity.

Mitigation and workarounds

OpenVPN released version 2.7.7 which addresses this and six other security flaws; users should upgrade to OpenVPN 2.7.7 or a patched 2.6.x release as soon as available (Linuxiac, OpenVPN Advisory). As interim mitigations: restrict local user access to systems running affected OpenVPN versions; implement application whitelisting (e.g., Windows Defender Application Control or AppLocker) to prevent execution of unauthorized binaries during OpenVPN network configuration; ensure that user-writable directories are not present earlier in the system PATH than trusted system directories; and run OpenVPN with the minimum necessary privileges (ENISA EUVD).

Community reactions

Security news outlets including CyberSecurityNews and The Daily Tech Feed covered the OpenVPN 2.7.7 release, noting it patched seven security flaws including CVE-2026-84226 affecting Windows systems (CyberSecurityNews, DailyTechFeed). The OpenVPN community forum also announced the 2.7.7 release (OpenVPN Forums). No significant independent researcher commentary or social media controversy has been observed around this specific CVE.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

openvpn

Fixed

sid

openvpn

Fixed

trixie

openvpn

Fixed

Alpine

Fixed

edge

openvpn: 0

Fixed

SourceThis report was generated using AI

Related OpenVPN vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84732HIGH8.7
  • OpenVPN logoOpenVPN
  • openvpn-auth-pam-plugin
NoYesSep 07, 2026
CVE-2026-84226HIGH8.5
  • OpenVPN logoOpenVPN
  • cpe:2.3:a:openvpn:openvpn
NoYesSep 07, 2026
CVE-2026-84256HIGH7.7
  • OpenVPN logoOpenVPN
  • cpe:2.3:a:openvpn:openvpn
NoYesSep 07, 2026
CVE-2026-82325MEDIUM6.8
  • OpenVPN logoOpenVPN
  • cpe:2.3:a:openvpn:openvpn
NoNoSep 07, 2026
CVE-2026-82312LOW1.8
  • OpenVPN logoOpenVPN
  • cpe:2.3:a:openvpn:openvpn
NoYesSep 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management