CVE-2026-63649
CVE-2026-63649: 1 tracked advisory record across Red Hat. Compare vendor sources.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityHigh8.8
High [CVE-2026-63649] Privilege escalation via arbitrary configuration file loading
CVE-2026-63649Source published Source updated
The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that bypass whitelist checks This bypass allows the user to load arbitrary configuration files, which could lead to privilege escalation or other system compromise. This Important vulnerability affects the Windows interactive service of OpenVPN, allowing a local authenticated user to bypass configuration file restrictions and achieve privilege escalation. This issue is specific to OpenVPN deployments on Microsoft Windows and does not directly impact Red Hat products, which primarily utilize OpenVPN on Linux-based systems. Red Hat severity: Important…
- Affected products in this advisory
- No product details extracted. Check the source bulletin.
- Source-reported affected versions
- 2.4.0
- 2.6.21
- 2.7.5
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.