Junglewise Threat Intelligence

CVE-2026-84226: OpenVPN binary planting on Windows

CVE-2026-84226 · Severity: info · Published 2026-09-07

Technologies: Openvpn. Vendors: Openvpn.

Executive brief

OpenVPN, a widely-used open-source VPN client and server software, contains a local privilege escalation vulnerability on Windows systems. An authenticated local attacker can exploit this flaw during network configuration to plant arbitrary binaries and potentially execute code with elevated privileges, compromising the security of systems running affected OpenVPN versions.

Technical details

This vulnerability is a binary planting / DLL hijacking issue affecting OpenVPN's network configuration routines on Windows. The vulnerability requires local authentication and occurs during network configuration steps, where the application fails to properly validate the source or integrity of binaries loaded from predictable paths. An authenticated local attacker can exploit this to plant malicious binaries in locations where OpenVPN or its network configuration utilities search for dependencies, potentially leading to arbitrary code execution. The flaw affects versions 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6; patched versions are expected to validate binary sources more strictly.

Affected products

  • OpenVPN OpenVPN 2.5.0 through 2.6.22, 2.7_alpha1 through 2.7.6 (Windows)

Timeline

  • 2026-09-07: disclosed

References

Related threats