OpenVPN 2.7_alpha1-2.7.6: Buf Size Defect in WIntSrv (CVE-2026-78221)
CVE-2026-78221 Published on September 7, 2026
An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.
Vulnerability Analysis
CVE-2026-78221 can be exploited with local system access. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Incorrect Calculation of Buffer Size
The software does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.
Products Associated with CVE-2026-78221
Want to know whenever a new CVE is published for OpenVPN? stack.watch will email you.
Affected Versions
OpenVPN:- Version 2.7_alpha1, <= 2.7.6 is affected.