Junglewise Threat Intelligence

CVE-2026-78043: OpenVPN Windows Interactive Service configuration bypass

CVE-2026-78043 · Severity: info · Published 2026-09-07

Technologies: Openvpn. Vendors: Openvpn.

Executive brief

OpenVPN's Windows Interactive Service, a component that runs as a system service on Windows systems, contains a flaw that allows local users with authentication credentials to load arbitrary configuration files by bypassing security restrictions. This could allow an authenticated attacker to modify VPN behavior, potentially redirecting traffic or accessing sensitive routing and credential information.

Technical details

The vulnerability is a path traversal / trust boundary bypass in the Windows Interactive Service component of OpenVPN 2.7_alpha1 through 2.7.6. The service enforces a trusted configuration directory constraint to prevent unprivileged users from loading arbitrary configuration files; however, specially crafted paths can be used to circumvent this restriction. The attack requires local authentication (an existing user account on the system) and does not require network access. A successful exploit allows an authenticated local user to load and execute arbitrary configuration files, potentially compromising the VPN client's security posture.

Affected products

  • OpenVPN OpenVPN 2.7_alpha1 through 2.7.6

Timeline

  • 2026-09-07: disclosed

References

Related threats