CVE-2026-84256: OS Command Injection
Published Sep 7, 2026
·Updated
An argument parsing issue in OpenVPN 2.1rc10 through 2.6.22 and 2.7alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject
Affected Software
1 affected component
OpenVPN OpenVPN>=2.1_rc10<=2.6.22, >=2.7_alpha1<=2.7.6
Event History
Sep 7, 2026
CVE Published
via MITRE·07:55 AM
Data Sourced
via MITRE·07:55 AM
DescriptionWeakness
Data Sourced
via NVD·08:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
The issue affects OpenVPN on Windows running versions 2.1_rc10 through 2.6.22, or 2.7_alpha1 through 2.7.6.
2
What access does an attacker need to exploit this issue?
An attacker must be a remote authenticated user and must be able to provide a certificate with a crafted subject.