Junglewise Threat Intelligence

CVE-2026-63649: OpenVPN Windows interactive service configuration bypass

CVE-2026-63649 · Severity: info · Published 2026-08-14

Technologies: Openvpn. Vendors: Openvpn.

Executive brief

OpenVPN's Windows interactive service, which manages VPN connections on Windows systems, contains a flaw that allows authenticated users on the same machine to load unauthorized configuration files. An attacker with local access could bypass security controls and potentially redirect VPN traffic or inject malicious settings, compromising the integrity of VPN connections.

Technical details

The vulnerability exists in the Windows interactive service component of OpenVPN, which validates configuration file paths against a whitelist. The flaw allows local authenticated users to craft options that bypass these whitelist checks, enabling them to load arbitrary configuration files outside the trusted configuration directory. An attacker must have local authentication to the system and the ability to supply options to the service. The attack vector is local, requiring existing user-level access. Patches are expected in future OpenVPN releases beyond the affected versions.

Affected products

  • OpenVPN OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5

Timeline

  • 2026-08-14: disclosed

References

Related threats