Description
An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.
Published: 2026-09-07
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An incorrect buffer size calculation in the Windows Interactive Service of OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to trigger memory corruption or expose sensitive data. The flaw is limited to NRPT handling, which can corrupt application memory or leak data to the attacker when supplied with specially crafted inputs. The primary consequence is potential compromise of local system integrity or confidentiality depending on the information revealed.

Affected Systems

The vulnerability affects the OpenVPN product, specifically the Windows Interactive Service component included in the 2.7_alpha1 to 2.7.6 releases. Users running these versions on Windows platforms are susceptible if the Interactive Service is enabled and NRPT inputs are accepted.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate severity. The attack requires local authentication, meaning it is limited to users who have logged into the Windows host. No public exploit is known, and the vulnerability is not listed in CISA KEV. Since EPSS is unavailable, exploitation likelihood cannot be precisely quantified, but the moderate score suggests that if an attacker can gain local access, the risk of successful exploitation is non‑negligible.

Generated by OpenCVE AI on September 7, 2026 at 08:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update OpenVPN to the latest stable release that corrects the NRPT buffer size calculation.
  • If an immediate update is not possible, disable the Windows Interactive Service and remove NRPT input handling from the configuration.
  • Restrict local user access to NRPT functions and monitor network traffic for abnormal NRPT activity.

Generated by OpenCVE AI on September 7, 2026 at 08:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Memory Corruption and Sensitive Information Disclosure via Crafted NRPT Inputs in Windows Interactive Service
First Time appeared Openvpn
Openvpn openvpn
Vendors & Products Openvpn
Openvpn openvpn

Mon, 07 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.
Weaknesses CWE-131
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: OpenVPN

Published:

Updated: 2026-09-07T07:28:14.135Z

Reserved: 2026-08-26T14:41:20.459Z

Link: CVE-2026-78221

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T08:17:12.813

Modified: 2026-09-07T08:17:12.813

Link: CVE-2026-78221

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T08:30:14Z

Weaknesses
  • CWE-131

    Incorrect Calculation of Buffer Size