OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field
Info
Summary
OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://community.openvpn.net/ReleaseHistory#openvpn-276-released-5-august-2026
- https://community.openvpn.net/Security%20Announcements/CVE-2026-63650
Timeline
- nvd_ingest NVD