CVE-2026-78221

An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.

Scoring

Severity
MEDIUM
CVSS base score
5.9
CVSS vector
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H
EPSS probability
0.12%
CWE
CWE-131
Published
2026-09-07
Last modified
2026-09-08

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs