Search/CVE-2026-63649
CVE

CVE-2026-63649

The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that bypass whitelist checks

CVSS v3.1
EPSS
0.24%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 16, 2026Aug 26, 2026
0.09pp
0.33% → 0.24% over 2 tracked changes
Connections
1 relationships
Timeline
disclosure → media coverage
Aug 14, 2026
Disclosure — published as a CVE record. · last revised by NVD Sep 1, 2026