ZeroHour

CVE-2026-84256

mass

Authenticated Command Injection in OpenVPN for Windows via Crafted Certificate Subject

CVSS 4.0
7.7 high
EPSS
<1%p32
Published
()
Modified
AI analysis

CVE-2026-84256 is an argument parsing flaw (CWE-78/CWE-88) in OpenVPN on Windows that lets a remote authenticated user execute arbitrary operating-system commands by presenting a certificate whose subject field is crafted to alter or extend the command line OpenVPN constructs. When an affected build (2.1_rc10 through 2.6.22, or 2.7_alpha1 through 2.7.6) on Windows processes the malicious subject during an authenticated session, injected metacharacters or arguments are carried into command execution on the host. Successful exploitation gives the attacker command execution with the privileges of the OpenVPN process, with High impact on confidentiality, integrity, and availability (CVSS 4.0 score 7.7). Affected parties are any Windows deployments of OpenVPN within the listed version ranges, particularly deployments where remote users authenticate. No exploitation is known: there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.4% probability of exploitation in the next 30 days.

What to do: Upgrade Windows OpenVPN deployments to a fixed release after 2.6.22 on the 2.6 branch and after 2.7.6 on the 2.7 branch as published by the OpenVPN CNA. Until patched, restrict remote authenticated access on affected Windows servers and review configurations that pass certificate subject data to external scripts or commands. Monitor OpenVPN advisories and telemetry for exploitation indicators, given the low but nonzero EPSS score.

Affected
OpenVPN (Windows)2.1_rc10 through 2.6.22
OpenVPN (Windows)2.7_alpha1 through 2.7.6
Estimated exposure
masslikely millions of Windows installations (estimate; the affected range spans roughly a decade of OpenVPN releases, but only authenticated-session scenarios are… — OpenVPN is among the most widely deployed VPN clients and servers, the affected ranges cover essentially all Windows builds from 2.1 through 2.6.22 plus 2.7 pre-releases, and Windows installs bundled by consumer VPN providers and used in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject

Weakness
CWE-78, CWE-88
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.