CVE-2026-78221: OpenVPN OpenVPN 2.7 vulnerability
Published Sep 7, 2026
·Updated
An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.
Affected Software
1 affected component
OpenVPN OpenVPN 2.7>=2.7_alpha1<=2.7.6
Event History
Sep 7, 2026
CVE Published
via MITRE·07:28 AM
Data Sourced
via MITRE·07:28 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Exploitation requires local authenticated access to a Windows system running an affected OpenVPN 2.7 release. The vulnerable component is the Windows Interactive Service.
2
What must an attacker provide to trigger the flaw?
An attacker needs to supply crafted NRPT inputs to reach the incorrect buffer size calculation in the Windows Interactive Service.
3
What are the potential impacts?
Successful exploitation may cause memory corruption or disclose sensitive information.