Junglewise Threat Intelligence

CVE-2026-63650: OpenVPN authentication identity lookup bypass in mbedTLS

CVE-2026-63650 · Severity: info · Published 2026-08-14

Technologies: Openvpn. Vendors: Openvpn.

Executive brief

OpenVPN is a widely-deployed VPN service used to provide secure remote access to corporate networks. A flaw in versions 2.7_alpha1 through 2.7.5 using the mbedTLS encryption library allows already-authenticated remote users to be misidentified by bypassing the configured X.509 certificate username lookup field, potentially enabling unauthorized access to resources intended for different users.

Technical details

The vulnerability is an authentication identity lookup bypass in OpenVPN's mbedTLS integration. When processing X.509 client certificates for authentication, the application fails to properly validate the configured username identity lookup field, allowing an authenticated attacker to spoof their identity. An attacker with valid VPN credentials can exploit this to impersonate other users whose credentials they do not possess. The attack requires prior network authentication and exploits a flaw in certificate identity validation logic. OpenVPN versions 2.7_alpha1 through 2.7.5 using mbedTLS are affected; patched versions should be available.

Affected products

  • OpenVPN OpenVPN 2.7_alpha1 through 2.7.5 (mbedTLS backend)

Timeline

  • 2026-08-14: disclosed

References

Related threats