CVE-2026-84226
massLocal Privilege Escalation via Binary Planting in OpenVPN for Windows
OpenVPN 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows contain an untrusted search path flaw (CWE-426) that allows a binary planting attack while OpenVPN performs its network configuration steps. A local authenticated user can plant a malicious executable or library in a location searched ahead of the legitimate binary, which is then executed or loaded when those configuration steps run. Because the affected components operate in the context of the OpenVPN service, the attacker gains code execution with elevated privileges on the host, yielding a full local privilege escalation with high impact on confidentiality, integrity and availability of that system. Only OpenVPN deployments on Windows are affected; other platforms are not listed as impacted. Exploitation status is currently quiet: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns roughly a 0.1% probability of exploitation in the next 30 days.
What to do: Windows administrators should upgrade OpenVPN to a release after 2.6.22 (2.6.x branch) or after 2.7.6 (2.7.x branch) as published by OpenVPN, since those are the last affected versions in each branch and no fixed version is specified in the available data. As an interim mitigation, verify that standard users cannot write to the directories on the binary/library search path used by the OpenVPN service during network configuration, and watch for unexpected executables placed there. Check your installed client version (visible in the client's About/help output) to determine whether you are in an affected range.
| OpenVPN Inc. OpenVPN (Windows client/service) | 2.5.0 through 2.6.22 |
| OpenVPN Inc. OpenVPN (Windows client/service) | 2.7_alpha1 through 2.7.6 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps
- Weakness
- CWE-426
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.