
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-84226 is a binary planting (untrusted search path) vulnerability in OpenVPN for Windows that allows local authenticated users to execute arbitrary code with elevated privileges during network configuration steps. It affects OpenVPN versions 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows. The vulnerability was published on September 7, 2026, and carries a CVSS v4.0 base score of 8.5 (High) (GitHub Advisory, ENISA EUVD).
The vulnerability is classified as CWE-426 (Untrusted Search Path), where OpenVPN on Windows searches for critical binaries or resources using a path that can be manipulated by a local user (GitHub Advisory). During network configuration steps — such as when OpenVPN invokes helper executables or scripts — an attacker can plant a malicious binary in a directory that OpenVPN searches before the legitimate binary location, causing the malicious binary to be executed instead. This technique maps to MITRE ATT&CK T1574.007 (Path Interception by PATH Environment Variable) and CAPEC-38 (Leveraging/Manipulating Configuration File Search Paths). Exploitation requires only low-level local authentication and no user interaction, making it straightforward for any authenticated Windows user on the affected system (ENISA EUVD).
Successful exploitation allows a local authenticated attacker to achieve arbitrary code execution with elevated privileges on the affected Windows system, resulting in high confidentiality, integrity, and availability impact to the vulnerable system (GitHub Advisory). An attacker could use this privilege escalation as a stepping stone for lateral movement, credential harvesting, or persistent access within the environment. The vulnerability does not affect subsequent/downstream systems directly, but the elevated access gained on the OpenVPN host could expose sensitive VPN credentials and network configuration data (ENISA EUVD).
As of the time of publication, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (ENISA EUVD). The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD SSVC assessment confirms exploitation status as "none" and automatable as "no" (GitHub Advisory). The EPSS score is approximately 0.142% (4th percentile), indicating a low near-term probability of exploitation. No threat actor attribution has been reported.
.exe files in user-writable directories on the PATH.openvpn.exe) or its service, especially processes not matching expected OpenVPN helper binaries; processes running with elevated privileges originating from user-writable directories.OpenVPN released version 2.7.7 which addresses this and six other security flaws; users should upgrade to OpenVPN 2.7.7 or a patched 2.6.x release as soon as available (Linuxiac, OpenVPN Advisory). As interim mitigations: restrict local user access to systems running affected OpenVPN versions; implement application whitelisting (e.g., Windows Defender Application Control or AppLocker) to prevent execution of unauthorized binaries during OpenVPN network configuration; ensure that user-writable directories are not present earlier in the system PATH than trusted system directories; and run OpenVPN with the minimum necessary privileges (ENISA EUVD).
Security news outlets including CyberSecurityNews and The Daily Tech Feed covered the OpenVPN 2.7.7 release, noting it patched seven security flaws including CVE-2026-84226 affecting Windows systems (CyberSecurityNews, DailyTechFeed). The OpenVPN community forum also announced the 2.7.7 release (OpenVPN Forums). No significant independent researcher commentary or social media controversy has been observed around this specific CVE.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."