AUGUST 21, 2026
Live Feed
Back to database
Case File

CVE-2026-13122

MEDIUM · CVSS 5.3 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-06 · Last synced 2026-08-05

CyberRota Analysis

AI-Generated

OpenVPN versions 2.6.0 to 2.6.20 and 2.7_alpha1 to 2.7.4 are vulnerable to a denial of service attack due to a malformed authentication token that can trigger a reachable assertion when the external-auth feature is enabled. This vulnerability could allow remote attackers to disrupt service availability. Organizations using affected versions of OpenVPN should prioritize patching to mitigate potential service interruptions.

CVE
CVE-2026-13122
Severity
MEDIUM
CVSS
5.3
EPSS
0.29%

Original NVD Description

OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled

Related CVEs

Other vulnerabilities affecting the same vendor(s)