CVE-2026-78043

unknown
Assigned by CNA: openvpn
Published 2026-09-07 · Modified 2026-09-07
CVSS v3
CVSS v4 NEW
5.6
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
VIR risk

Description

The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2026-78043 NameCVE-2026-78043 SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed packages The table below lists information on source packages. Source PackageReleaseVersionStatus openvpn (PTS)bookworm, bookworm (security)2.6.14-0+deb12u2fixed trixie (security),…

CVE-2026-78043

NameCVE-2026-78043
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
openvpn (PTS)bookworm, bookworm (security)2.6.14-0+deb12u2fixed
trixie (security), trixie2.6.14-1+deb13u3fixed
forky2.7.5-1fixed
sid2.7.7-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
openvpnsource(unstable)(not affected)

Notes

- openvpn <not-affected> (Only affects OpenVPN on Windows)

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
- openvpn <not-affected> (Only affects OpenVPN on Windows)

OS impact

debian Debian Fixed 4 releases
VersionStatusFixed in
trixie Fixed 0
sid Fixed 0
forky Fixed 0
bookworm Fixed 0

References

CWEs

CWE-22

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.