What is CVE-2026-63650?
CVE-2026-63650 is an authentication vulnerability in OpenVPN versions using mbedTLS where the configured X.509 username identity lookup field is ignored. This allows remote authenticated users to be misidentified. It is recommended to update OpenVPN to the latest version.
Azərbaycanca: CVE-2026-63650 OpenVPN-in mbedTLS istifadə edən versiyalarında autentifikasiya zəifliyidir. Bu qüsur uzaqdan autentifikasiya olunmuş istifadəçilərin X.509 istifadəçi adı identifikasiya sahəsini nəzərə almamaqla səhv identifikasiya olunmasına səbəb olur. Təsirə məruz qalmamaq üçün OpenVPN-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which TLS library does the CVE-2026-63650 vulnerability affect in OpenVPN versions?
It affects versions using the mbedTLS library.
What is the recommended mitigation for CVE-2026-63650?
It is recommended to update OpenVPN to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.