CVE-2026-84226

Description

A flaw was found in OpenVPN on Windows. A local authenticated user could perform a binary planting attack during network configuration steps. This vulnerability could allow the attacker to execute arbitrary code or escalate privileges on the affected system.

Statement

The vulnerability is rated as Important because it allows local authenticated users to achieve arbitrary code execution via a binary planting attack during network configuration steps. However, this flaw specifically affects OpenVPN on Windows platforms. Red Hat's OpenVPN packages, available in Community Projects like Fedora and EPEL, are built for Linux environments and are not susceptible to this Windows-specific vulnerability.

Understanding the Weakness (CWE)

Integrity,Confidentiality,Availability,Access Control

Technical Impact: Gain Privileges or Assume Identity; Execute Unauthorized Code or Commands

There is the potential for arbitrary code execution with privileges of the vulnerable program.

Availability

Technical Impact: DoS: Crash, Exit, or Restart

The program could be redirected to the wrong files, potentially triggering a crash or hang when the targeted file is too large or does not have the expected format.

Confidentiality

Technical Impact: Read Files or Directories

The program could send the output of unauthorized files to the attacker.

Frequently Asked Questions

Want to get errata notifications? Sign up here.