CVE-2026-63649
CVE-2026-63649 is a medium-severity vulnerability with a CVSS 4.0 base score of 4.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-183.
Key facts
- Severity: Medium (CVSS 4.0 base score 4.1)
- EPSS exploit prediction: 0% (26th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-183
- Published:
- Last modified:
Description
The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that bypass whitelist checks
Frequently asked questions
- What is CVE-2026-63649?
- The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that bypass whitelist checks
- How severe is CVE-2026-63649?
- CVE-2026-63649 has a CVSS 4.0 base score of 4.1, rated medium severity.
- Is CVE-2026-63649 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (26th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-63649?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-63649 published?
- CVE-2026-63649 was published on 2026-08-14 and last updated on 2026-08-17.
References
- https://community.openvpn.net/ReleaseHistory#openvpn-2622-released-5-august-2026
- https://community.openvpn.net/ReleaseHistory#openvpn-276-released-5-august-2026
- https://community.openvpn.net/Security%20Announcements/CVE-2026-63649
Other CWE-183 vulnerabilities
- CVE-2026-3490 — Critical (CVSS 10.0): picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by…
- CVE-2026-54316 — Critical (CVSS 9.1): Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved…
- CVE-2026-29514 — High (CVSS 8.8): NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the…
- CVE-2026-46391 — High (CVSS 8.7): HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 9.0.1 and prior to version…
- CVE-2025-53762 — High (CVSS 8.7): Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a…
- CVE-2026-59802 — High (CVSS 8.2): PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the…