CVE-2026-84226: OpenVPN OpenVPN vulnerability
Published Sep 7, 2026
·Updated
OpenVPN version 2.5.0 through 2.6.22 and 2.7alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps
Affected Software
1 affected component
OpenVPN OpenVPN>=2.5.0<=2.6.22, >=2.7_alpha1<=2.7.6
Event History
Sep 7, 2026
CVE Published
via MITRE·07:47 AM
Data Sourced
via MITRE·07:47 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A local authenticated user on a Windows system running an affected OpenVPN version can exploit it. The issue is associated with OpenVPN network configuration steps.
2
Which OpenVPN releases are affected?
Affected releases are OpenVPN 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows.