Junglewise Threat Intelligence

CVE-2026-82312: OpenVPN denial of service via NULL DACL on Windows IPC

CVE-2026-82312 · Severity: info · Published 2026-09-07

Technologies: Openvpn. Vendors: Openvpn.

Executive brief

OpenVPN is a widely-used open-source VPN application that secures network traffic. On Windows systems, versions 2.0.0 through 2.6.22 and 2.7 alpha versions through 2.7.6 allow authenticated local users to disrupt VPN service availability by exploiting improper permissions on named inter-process communication objects.

Technical details

This vulnerability affects OpenVPN's handling of Windows named IPC objects, which use NULL DACL (Discretionary Access Control List) for permission management. The weakness allows any local authenticated user on the system to interfere with these IPC channels, leading to denial of service against the VPN service. The attack requires local system access and authentication but does not require network access. An attacker can crash or disable the OpenVPN service, disrupting VPN connectivity for legitimate users. Patches are available in newer versions beyond 2.6.22 and 2.7.6.

Affected products

  • OpenVPN OpenVPN 2.0.0 through 2.6.22, 2.7_alpha1 through 2.7.6 on Windows

Timeline

  • 2026-09-07: disclosed

References

Related threats