Description
OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps
Published: 2026-09-07
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Local code execution
Action: Patch
AI Analysis

Impact

The vulnerability arises from an implementation flaw in OpenVPN for Windows that permits a local authenticated user to perform a binary planting attack during the network configuration process. This flaw allows the attacker to place a malicious executable in a location where OpenVPN will later invoke it, resulting in code execution with the privileges of the OpenVPN process. The identified weakness is classified as CWE‑426, indicating an untrusted search path.

Affected Systems

Affected across Windows deployments are OpenVPN releases 2.5.0 through 2.6.22 and the 2.7_alpha1 through 2.7.6 branches. Users running any of these versions on Windows must assess whether they are exposed.

Risk and Exploitability

The CVSS score of 8.5 signals a high severity impact, and the vulnerability is not listed in the CISA KEV catalog. EPSS data is unavailable, so the current probability of exploitation is unknown, but the local nature of the attack coupled with the ability to plant binaries suggests that a capable user with local administrative or configuration privileges could exploit the flaw with relative ease. The attack vector is local; it requires the attacker to authenticate to the host and modify network configuration or related directories, after which the malicious binary will be executed.

Generated by OpenCVE AI on September 7, 2026 at 13:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a version of OpenVPN that contains the fix for CVE‑2026‑84226 or a newer release.
  • Limit local user permissions so that only trusted administrators can perform network configuration changes and modify directories that OpenVPN uses during setup.
  • Configure the system to use a trusted binary search path, ensuring that OpenVPN only loads executables from known secure directories.
  • As a temporary measure, disable any scripts or automated configuration features that allow user‑supplied binaries to be executed during the network configuration process.

Generated by OpenCVE AI on September 7, 2026 at 13:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title OpenVPN Windows Binary Planting vulnerability allows local code execution during configuration OpenVPN: OpenVPN: Arbitrary Code Execution via Binary Planting on Windows
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Mon, 07 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Openvpn
Openvpn openvpn
Vendors & Products Openvpn
Openvpn openvpn

Mon, 07 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Title OpenVPN Windows Binary Planting vulnerability allows local code execution during configuration

Mon, 07 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps
Weaknesses CWE-426
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: OpenVPN

Published:

Updated: 2026-09-08T14:59:53.551Z

Reserved: 2026-09-01T11:57:34.684Z

Link: CVE-2026-84226

cve-icon Vulnrichment

Updated: 2026-09-08T14:59:47.752Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-07T08:17:13.653

Modified: 2026-09-08T19:07:52.113

Link: CVE-2026-84226

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-07T07:47:04Z

Links: CVE-2026-84226 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T14:30:17Z

Weaknesses