OpenVPN 2.0.0-2.7.6 Windows NULL DACL IPC Denial of Service
CVE-2026-82312 Published on September 7, 2026
OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of service via a NULL DACL on named IPC objects
Vulnerability Analysis
CVE-2026-82312 is exploitable with local system access. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Types
Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. When a resource is given a permissions setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution or sensitive user data.
Unrestricted Externally Accessible Lock
The software properly checks for the existence of a lock, but the lock can be externally controlled or influenced by an actor that is outside of the intended sphere of control. This prevents the software from acting on associated resources or performing other behaviors that are controlled by the presence of the lock. Relevant locks might include an exclusive lock or mutex, or modifying a shared resource that is treated as a lock. If the lock can be held for an indefinite period of time, then the denial of service could be permanent.
Products Associated with CVE-2026-82312
Want to know whenever a new CVE is published for OpenVPN? stack.watch will email you.
Affected Versions
OpenVPN:- Version 2.0.0, <= 2.6.22 is affected.
- Version 2.7_alpha1, <= 2.7.6 is affected.