CVE-2026-81830 - Windows openvpnserv config path validation bypass via sibling directories

OpenVPN 2.x on Windows allows local users to start openvpn.exe with a config file outside the administratively allowed config directories, because CheckConfigPath() in openvpnserv did not detect and refuse sibling directories of an allowed path.

OpenVPN version 2.4.0 through 2.6.22 are affected. This is fixed in version 2.6.23 <2.7.x FIXED VERSION TBD>.

CVE Record: CVE-2026-81830

Github:

Release notes:

Reported-By: Harshit Varu

0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9