<Vulnerability name="CVE-2026-81830">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-09-07T07:36:19</PublicDate>
    <Bugzilla id="2529302" url="https://bugzilla.redhat.com/show_bug.cgi?id=2529302" xml:lang="en:us">
OpenVPN: OpenVPN: Security Bypass via incorrect file path validation
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>5.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-22</CWE>
    <Details xml:lang="en:us" source="Mitre">
The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in OpenVPN. The Windows interactive service in OpenVPN contains an incorrect file path validation vulnerability. A local authenticated user could exploit this flaw to bypass the trusted configuration directory constraint, leading to a security bypass and potential integrity compromise.
    </Details>
    <Statement xml:lang="en:us">
This Moderate vulnerability affects the Windows interactive service in OpenVPN, allowing local authenticated users to bypass trusted configuration directory constraints. As this issue is specific to the Windows platform, it does not directly impact Red Hat products.
    </Statement>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-81830
https://nvd.nist.gov/vuln/detail/CVE-2026-81830
https://community.openvpn.net/Security%20Announcements/CVE-2026-81830
    </References>
</Vulnerability>