Auth Misidentification in OpenVPN 2.712.7.5 via mbedTLS
CVE-2026-63650 Published on August 14, 2026
OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field
Vulnerability Analysis
CVE-2026-63650 is exploitable with network access. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Types
Improper Certificate Validation
The software does not validate, or incorrectly validates, a certificate. When a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host.
Misinterpretation of Input
The software misinterprets an input, whether from an attacker or another product, in a security-relevant fashion.
Products Associated with CVE-2026-63650
Want to know whenever a new CVE is published for OpenVPN? stack.watch will email you.
Affected Versions
OpenVPN:- Version 2.7_alpha1 and below 2.7.6 is affected.