CVE-2026-81830CWE-73

The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via…

Medium · published September 7, 2026

CVSS v4.0
5.6
EPSS
In the wild
Unconfirmed
What it is

The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation

The record
Technical detail
CVSS v4.0
5.6 · MEDIUM
Vector
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
EPSS
Not scored
Weakness
CWE-73 · External Control of File Name or Path
Published
2026-09-07T07:36Z
Timeline
  • 07 SEP 07:36Z
    The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via…
    cvelistv5