CVE-2026-63649: OpenVPN OpenVPN vulnerability
Published Aug 14, 2026
·Updated
The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that bypass whitelist checks
Affected Software
1 affected component
OpenVPN OpenVPN>=2.4.0<=2.6.21, >=2.7_alpha1<=2.7.5
Event History
Aug 14, 2026
CVE Published
via MITRE·10:13 PM
Data Sourced
via MITRE·10:13 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-63649?
CVE-2026-63649 is rated with a risk score of 39.
2
How do I fix CVE-2026-63649?
The recommended fix for CVE-2026-63649 is to upgrade to OpenVPN versions 2.7.6 or higher.
3
What vulnerabilities are associated with CVE-2026-63649?
CVE-2026-63649 allows local authenticated users to load arbitrary configuration files by bypassing trusted configuration directory constraints.
4
Which versions of OpenVPN are affected by CVE-2026-63649?
OpenVPN versions 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 are affected by CVE-2026-63649.
5
When was CVE-2026-63649 published?
CVE-2026-63649 was published on August 14, 2026.