LOWVulnerability
CVE-2026-63649
The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that bypass whitelist checks
Properties
- epss_score
- 0.00235
- cve_id
- CVE-2026-63649
- published_at
- 2026-08-14T23:16:32.507
- last_modified
- 2026-09-01T21:03:04.987
- epss_percentile
- 0.14376
Related Entities (3)
ENRICHED_BY (1)
→[Source]FIRST EPSS
HAS_WEAKNESS (1)
→[Weakness]Permissive List of Allowed Inputs
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph