CVE-2026-84256 - Windows CreateProcess() command line quoting bypass via cmd.exe metacharacters
OpenVPN 2.x on Windows does not correctly quote command lines passed to CreateProcess() for characters that are special to cmd.exe. In combination with a validation script and a rogue CA, this could be used to make OpenVPN misbehave.
OpenVPN version 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 are affected. This is fixed in version 2.7.7.
CVE Record: CVE-2026-84256
Github:
Release notes:
Reported-By: Clouditera Security
