Junglewise Threat Intelligence

CVE-2026-9560: OpenVPN Connect privilege escalation in macOS background service

CVE-2026-9560 · Severity: info · CVSS 9.4 · Published 2026-05-26

Vendors: Openvpn.

Executive brief

A security vulnerability in the OpenVPN Connect application for macOS could allow a local user to gain administrative control over the computer. The issue exists in a background service used by the VPN client, which can be tricked into running unauthorized commands with high-level system privileges. This could lead to a full system takeover, allowing an attacker to access sensitive data or install malicious software.

Technical details

A privilege escalation vulnerability exists in the macOS version of OpenVPN Connect (versions 3.5.1 through 3.8.1) within its privileged helper component. The flaw stems from improper neutralization of special elements used in OS commands (CWE-78) and incorrect use of privileged APIs (CWE-648) within the local Inter-Process Communication (IPC) channel. A local attacker can send specially crafted messages to the background service's IPC channel to execute arbitrary commands with the privileges of the helper service (typically root). This bypasses standard macOS permission boundaries. The issue is resolved in OpenVPN Connect version 3.8.2 (6009).

Affected products

  • OpenVPN OpenVPN Connect 3.5.1 through 3.8.1

Timeline

  • 2026-05-25: patched: Fixed in version 3.8.2 (6009)
  • 2026-05-26: disclosed: CVE published

References