LOW 2.0 NVD
CVE-2026-63650
OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup f
OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field
References
- https://community.openvpn.net/ReleaseHistory#openvpn-276-released-5-august-2026
- https://community.openvpn.net/Security%20Announcements/CVE-2026-63650
This low severity vulnerability with a CVSS score of 2.0 was published on 2026-08-14 via NVD.
vulnfeed aggregates 10939 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.