Auth Misidentification in OpenVPN 2.712.7.5 via mbedTLS
CVE-2026-63650 Published on August 14, 2026

OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-63650 is exploitable with network access. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
LOW
User Interaction:
ACTIVE

Weakness Types

Improper Certificate Validation

The software does not validate, or incorrectly validates, a certificate. When a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host.

Misinterpretation of Input

The software misinterprets an input, whether from an attacker or another product, in a security-relevant fashion.


Products Associated with CVE-2026-63650

Want to know whenever a new CVE is published for OpenVPN? stack.watch will email you.

 

Affected Versions

OpenVPN: