CVE-2026-63650

Description

A flaw was found in OpenVPN when using mbedTLS. A remote authenticated user could be misidentified due to the software ignoring the configured X.509 username identity lookup field. This could lead to incorrect user authentication and potential security bypasses.

Statement

This flaw is rated as Low impact because it requires a remote authenticated user and high attack complexity to exploit. OpenVPN, when configured with mbedTLS, may incorrectly identify users by disregarding the X.509 identity field, potentially leading to unauthorized access under specific, complex conditions.

Understanding the Weakness (CWE)

Access Control

Technical Impact: Bypass Protection Mechanism

Frequently Asked Questions

Want to get errata notifications? Sign up here.