OpenVPN Plugin Vulnerability in openvpn-auth-oauth2 for OIDC Authentication by OpenVPN

⚠️ CVE-Referenzen: CVE-2026-41070
Jkroepke - Openvpn-auth-oauth2 - CRITICAL - CVE-2026-41070. The openvpn-auth-oauth2 plugin for OpenVPN, when deployed in experimental plugin mode, allows clients that lack support for WebAuth and Single Sign-On (SSO) to be improperly admitted to the VPN. This occurs even when the authentication logic denies access, creating a potential security risk. The issue is specific to versions ranging from 1.26.3 to just before 1.27.3 and does not affect the default management-interface mode. The vulnerability has been addressed in version 1.27.3.
Quelle: securityvulnerability.io