CVE-2026-82312: OpenVPN OpenVPN vulnerability
Published Sep 7, 2026
·Updated
OpenVPN 2.0.0 through 2.6.22 and 2.7alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of service via a NULL DACL on named IPC objects
Affected Software
1 affected component
OpenVPN OpenVPN>=2.0.0<=2.6.22, >=2.7_alpha1<=2.7.6
Event History
Sep 7, 2026
CVE Published
via MITRE·07:40 AM
Data Sourced
via MITRE·07:40 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must be a local authenticated user on a Windows system running an affected OpenVPN version. The described impact is denial of service through named IPC objects with a NULL DACL.
2
Which deployments are affected?
The issue affects OpenVPN on Windows in versions 2.0.0 through 2.6.22, and 2.7_alpha1 through 2.7.6. The provided information does not identify any configuration prerequisite beyond running an affected version on Windows.
3
Can this be exploited remotely?
The provided description identifies this as a local issue and requires an authenticated local user. It does not describe a remote attack path.