Junglewise Threat Intelligence

CVE-2026-41070: jkroepke openvpn-auth-oauth2 authentication bypass in plugin mode

CVE-2026-41070 · Severity: critical · CVSS 10 · Published 2026-05-08

Vendors: Go.

Executive brief

openvpn-auth-oauth2 is a tool that allows OpenVPN servers to use modern Single Sign-On (SSO) for user logins. A critical security flaw in its experimental plugin mode allows users to bypass the login process entirely if they use a connection client that does not support SSO. This could allow an unauthorized person to gain full access to your internal corporate network without providing any valid credentials.

Technical details

An authentication bypass exists in openvpn-auth-oauth2 versions 1.26.3 through 1.27.2 when deployed in experimental plugin mode. The vulnerability occurs because the plugin incorrectly returns 'OPENVPN_PLUGIN_FUNC_SUCCESS' to the OpenVPN server even when authentication is denied for clients that do not support WebAuth/SSO (such as the Linux OpenVPN CLI). Because OpenVPN interprets this return code as immediate approval without checking the underlying authentication control file, the connection is granted full network access. This issue does not affect the default management-interface mode. A fix is available in version 1.27.3, which correctly returns an error code upon authentication denial.

Affected products

  • jkroepke openvpn-auth-oauth2 >= 1.26.3, < 1.27.3

Timeline

  • 2026-04-17: advisory: GitHub Security Advisory published
  • 2026-05-08: disclosed: CVE published to NVD
  • 2026-05-08: patched: Fix commit 36f69a6 released

References