Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-63649

Опубликовано: 14 авг. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий

Описание

The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that bypass whitelist checks

РелизСтатусПримечание
devel

not-affected

windows only
esm-infra-legacy/trusty

not-affected

windows only
esm-infra-legacy/xenial

not-affected

windows only
esm-infra/bionic

not-affected

windows only
esm-infra/focal

not-affected

windows only
jammy

not-affected

windows only
noble

not-affected

windows only
resolute

not-affected

windows only
upstream

not-affected

debian: Only affects OpenVPN on Windows

Показывать по

EPSS

Процентиль: 14%
0.00235
Низкий

Связанные уязвимости

CVSS3: 8.8
redhat
20 дней назад

The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that bypass whitelist checks

nvd
20 дней назад

The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that bypass whitelist checks

debian
20 дней назад

The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2. ...

github
20 дней назад

The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that bypass whitelist checks

EPSS

Процентиль: 14%
0.00235
Низкий