Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-81830

Опубликовано: 07 сент. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation

A flaw was found in OpenVPN. The Windows interactive service in OpenVPN contains an incorrect file path validation vulnerability. A local authenticated user could exploit this flaw to bypass the trusted configuration directory constraint, leading to a security bypass and potential integrity compromise.

Отчет

This Moderate vulnerability affects the Windows interactive service in OpenVPN, allowing local authenticated users to bypass trusted configuration directory constraints. As this issue is specific to the Windows platform, it does not directly impact Red Hat products.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2529302OpenVPN: OpenVPN: Security Bypass via incorrect file path validation

EPSS

Процентиль: 1%
0.00106
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

ubuntu
8 дней назад

The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation

nvd
9 дней назад

The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation

debian
9 дней назад

The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows ...

github
9 дней назад

The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation

EPSS

Процентиль: 1%
0.00106
Низкий

5.5 Medium

CVSS3