CVE-2026-63650

OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-14 23:16

Updated : 2026-09-01 21:03


NVD link : CVE-2026-63650

Mitre link : CVE-2026-63650

CVE.ORG link : CVE-2026-63650


JSON object : View

Products Affected

No product.

CWE
CWE-115

Misinterpretation of Input

CWE-295

Improper Certificate Validation