AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-63650

LOW · CVSS 2

Source: NVD + CISA KEV + EPSS · Published 2026-08-14 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

OpenVPN versions 2.7_alpha1 through 2.7.5 using mbedTLS are vulnerable to a misidentification issue, where remote authenticated users can bypass the configured X.509 username identity lookup field. This flaw could lead to unauthorized access or privilege escalation, as users may be incorrectly identified. Organizations utilizing these OpenVPN versions should prioritize remediation to mitigate potential security risks.

CVE
CVE-2026-63650
Severity
LOW
CVSS
2
EPSS
N/A

Original NVD Description

OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field