CVE-2026-9560CWE-267CWE-270CWE-648CWE-78

Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated…

Critical · published May 26, 2026

CVSS v4.0
9.4
EPSS
1%
Percentile
45.2
In the wild
Unconfirmed
What it is

Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel

The record
Technical detail
CVSS v4.0
9.4 · CRITICAL
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
EPSS
0.00574 · 45.2th percentile
Weaknesses
CWE-267 · Privilege Defined With Unsafe Actions; CWE-270 · Privilege Context Switching Error; CWE-648 · Incorrect Use of Privileged APIs; CWE-78 · Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Published
2026-05-26T17:39Z
EPSS history
Timeline
  • 26 MAY 17:39Z
    Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated…
    cvelistv5