
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-84256 is an argument injection/OS command injection vulnerability in OpenVPN for Windows that allows remote authenticated users to execute arbitrary commands via a crafted certificate subject. It affects OpenVPN versions 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows platforms. The vulnerability was published on September 7, 2026, and carries a CVSS v4.0 base score of 7.7 (High) (GitHub Advisory, Feedly).
The root cause is improper argument parsing when processing certificate subject fields, classified under CWE-78 (OS Command Injection) and CWE-88 (Argument Injection). When OpenVPN on Windows processes a TLS certificate's subject field, it fails to properly neutralize special characters or argument delimiters, allowing an attacker-controlled certificate subject to inject additional OS-level commands or arguments into an underlying system call. Exploitation requires the attacker to be an authenticated user (low privileges) and certain deployment conditions must be present (Attack Requirements: Present), meaning the attacker must be able to present a crafted certificate to the server (GitHub Advisory).
Successful exploitation grants a remote authenticated attacker the ability to execute arbitrary OS commands on the Windows system running OpenVPN, resulting in high impact to confidentiality, integrity, and availability of the vulnerable system. An attacker could leverage this to exfiltrate sensitive data, modify system configurations, install malware, or disrupt VPN service availability. Because OpenVPN servers often serve as network access gateways, compromise could facilitate lateral movement into internal network segments (GitHub Advisory, Feedly).
As of the time of publication, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.383% (32nd percentile), indicating a relatively low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is not automatable (per NVD SSVC assessment) as it requires an authenticated user with the ability to present a crafted certificate.
&, |, ;, or extra arguments exploiting Windows argument parsing).&, |, ;, %, extra spaces, or flag-like strings); unexpected authentication events from unknown certificate subjects.cmd.exe, powershell.exe, net.exe) on Windows; unexpected network connections initiated by the OpenVPN process.OpenVPN has released version 2.7.7 (and a corresponding 2.6.x patch) addressing this and six other security flaws; upgrading to the patched release is the primary recommended remediation (Linuxiac, OpenVPN Forums). As interim workarounds, administrators should review and restrict certificate issuance procedures to ensure only trusted, properly validated certificates are accepted, and implement strict certificate subject validation policies. Monitoring OpenVPN logs for anomalous certificate subject values and restricting network access to the OpenVPN management interface can reduce exposure while patching is planned.
Security news outlets including CyberSecurityNews and The Daily Tech Feed covered the OpenVPN 2.7.7 release, noting it addressed seven security flaws including Windows-specific issues (CyberSecurityNews, DailyTechFeed). Linuxiac also published coverage of the release highlighting the security fixes (Linuxiac). No notable individual researcher commentary or significant social media discussion has been identified at this time.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."