What is CVE-2026-63649?
CVE-2026-63649 is a vulnerability in the Windows interactive service for OpenVPN, allowing local authenticated users to bypass trusted configuration directory constraints and load arbitrary configuration files through crafted options that evade whitelist checks. This affects OpenVPN versions 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5. Upgrading to the latest version and restricting local user access is advised to mitigate the risk.
Azərbaycanca: CVE-2026-63649 Windows-da işləyən OpenVPN interaktiv xidmətində aşkar edilmiş, lokal autentifikasiya olunmuş istifadəçilərə etibarlı konfiqurasiya qovluğu məhdudiyyətini keçərək ixtiyari konfiqurasiya fayllarını yükləməyə imkan verən zəiflikdir. Bu, xüsusi hazırlanmış opsiyalar vasitəsilə whitelist yoxlamalarından yan keçməklə həyata keçirilir və OpenVPN-in 2.4.0-dən 2.6.21-ə qədər, eləcə də 2.7_alpha1-dən 2.7.5-ə qədər versiyalarını təsirləyir. Təsirə məruz qalmamaq üçün OpenVPN müştərilərini ən son versiyaya yeniləmək və lokal istifadəçi girişlərini məhdudlaşdırmaq tövsiyə olunur.
Related CVEs
link basis: shared vendor: OpenVPN
FAQ2
On which platform is the interactive service affected by CVE-2026-63649?
The vulnerability is found in the Windows interactive service of OpenVPN.
To which versions should users upgrade to mitigate CVE-2026-63649?
Users should upgrade to versions above 2.6.21 for the 2.6 branch and above 2.7.5 for the 2.7 branch.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.