OpenVPN 2.4.0-2.6.22 Windows InterSvc FilePath Validation Bypass
CVE-2026-81830 Published on September 7, 2026

The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-81830 is exploitable with local system access. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
LOCAL
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
PASSIVE

Weakness Type

External Control of File Name or Path

The software allows user input to control or influence paths or file names that are used in filesystem operations.


Products Associated with CVE-2026-81830

Want to know whenever a new CVE is published for OpenVPN? stack.watch will email you.

 

Affected Versions

OpenVPN: