CVE-2026-84256
massAuthenticated Command Injection in OpenVPN for Windows via Crafted Certificate Subject
CVE-2026-84256 is an argument parsing flaw (CWE-78/CWE-88) in OpenVPN on Windows that lets a remote authenticated user execute arbitrary operating-system commands by presenting a certificate whose subject field is crafted to alter or extend the command line OpenVPN constructs. When an affected build (2.1_rc10 through 2.6.22, or 2.7_alpha1 through 2.7.6) on Windows processes the malicious subject during an authenticated session, injected metacharacters or arguments are carried into command execution on the host. Successful exploitation gives the attacker command execution with the privileges of the OpenVPN process, with High impact on confidentiality, integrity, and availability (CVSS 4.0 score 7.7). Affected parties are any Windows deployments of OpenVPN within the listed version ranges, particularly deployments where remote users authenticate. No exploitation is known: there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.4% probability of exploitation in the next 30 days.
What to do: Upgrade Windows OpenVPN deployments to a fixed release after 2.6.22 on the 2.6 branch and after 2.7.6 on the 2.7 branch as published by the OpenVPN CNA. Until patched, restrict remote authenticated access on affected Windows servers and review configurations that pass certificate subject data to external scripts or commands. Monitor OpenVPN advisories and telemetry for exploitation indicators, given the low but nonzero EPSS score.
| OpenVPN (Windows) | 2.1_rc10 through 2.6.22 |
| OpenVPN (Windows) | 2.7_alpha1 through 2.7.6 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject
- Weakness
- CWE-78, CWE-88
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.