CVE Vulnerabilities

CVE-2026-63650

Misinterpretation of Input

Published: Aug 14, 2026 | Modified: Aug 14, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field

Weakness

The product misinterprets an input, whether from an attacker or another product, in a security-relevant fashion.

References