CVE-2026-81830CWE-73
The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via…
Medium · published September 7, 2026
What it is
The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation
The record
Technical detail
- CVSS v4.0
- 5.6 · MEDIUM
- Vector
- CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
- EPSS
- Not scored
- Weakness
- CWE-73 · External Control of File Name or Path
- Published
- 2026-09-07T07:36Z
Timeline