CVE-2026-63650: OpenVPN OpenVPN vulnerability
Published Aug 14, 2026
·Updated
OpenVPN 2.7alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field
Affected Software
1 affected component
OpenVPN OpenVPN>=2.7_alpha1<=2.7.5
Event History
Aug 14, 2026
CVE Published
via MITRE·10:13 PM
Data Sourced
via MITRE·10:13 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-63650?
CVE-2026-63650 has a risk rating of 37, indicating a moderate threat level.
2
How do I fix CVE-2026-63650?
To fix CVE-2026-63650, update OpenVPN to version 2.7.6 or later, which addresses this vulnerability.
3
What system versions are affected by CVE-2026-63650?
CVE-2026-63650 affects OpenVPN versions 2.7_alpha1 through 2.7.5.
4
What issues does CVE-2026-63650 cause?
CVE-2026-63650 allows remote authenticated users to be misidentified due to an issue with the X.509 username identity lookup.
5
Who is impacted by CVE-2026-63650?
Users of OpenVPN versions between 2.7_alpha1 and 2.7.5 may be at risk due to CVE-2026-63650.