<Vulnerability name="CVE-2026-84226">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-09-07T07:47:04</PublicDate>
    <Bugzilla id="2529304" url="https://bugzilla.redhat.com/show_bug.cgi?id=2529304" xml:lang="en:us">
OpenVPN: OpenVPN: Arbitrary Code Execution via Binary Planting on Windows
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>7.8</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-426</CWE>
    <Details xml:lang="en:us" source="Mitre">
OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in OpenVPN on Windows. A local authenticated user could perform a binary planting attack during network configuration steps. This vulnerability could allow the attacker to execute arbitrary code or escalate privileges on the affected system.
    </Details>
    <Statement xml:lang="en:us">
The vulnerability is rated as Important because it allows local authenticated users to achieve arbitrary code execution via a binary planting attack during network configuration steps. However, this flaw specifically affects OpenVPN on Windows platforms. Red Hat's OpenVPN packages, available in Community Projects like Fedora and EPEL, are built for Linux environments and are not susceptible to this Windows-specific vulnerability.
    </Statement>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-84226
https://nvd.nist.gov/vuln/detail/CVE-2026-84226
https://community.openvpn.net/Security%20Announcements/CVE-2026-84226
    </References>
</Vulnerability>