CVE-2026-78043: Path Traversal
The Windows Interactive Service in OpenVPN 2.7alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be a local authenticated user on Windows. The affected component is the Windows Interactive Service in the listed OpenVPN versions.
What does an attacker need to do to exploit it?
The attacker needs to provide a specially crafted path that bypasses the trusted configuration directory constraint, allowing an arbitrary configuration file to be loaded.
Are all OpenVPN deployments affected?
The issue is described for the Windows Interactive Service, so deployments not using that Windows component are not identified as affected by the provided information. The affected version range is OpenVPN 2.7_alpha1 through 2.7.6.