CVE-2026-41070

CRITICAL

openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows. From version 1.26.3 to before version 1.27.3, when openvpn-au...

Affects 0 products across 4 vendors.

BCS6.13
CVSS 3.110.0
EPSS0.4%
Percentile36th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, no availability impact.
CWE Weakness Definitions
CWE-287: Improper Authentication

Software does not prove or insufficiently proves that the user is who they claim to be.

Related Attack Patterns (CAPEC)
CAPEC-57 Utilizing REST's Trust in the System Resource to Obtain Sensitive Data
via CWE-287
CAPEC-633 Token Impersonation
via CWE-287
CAPEC-650 Upload a Web Shell to a Web Server
via CWE-287
CAPEC-194 Fake the Source of Data
via CWE-287
CAPEC-593 Session Hijacking
via CWE-287
Show all 10

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability in openvpn-auth-oauth2 versions 1.26.3 to 1.27.2 allows unauthorized access when deployed in experimental plugin mode, affecting clients that do not support WebAuth/SSO.

BSID: BS-2026-GLOBAL-152408-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-41070?
A critical vulnerability in openvpn-auth-oauth2 versions 1.26.3 to 1.27.2 allows unauthorized access when deployed in experimental plugin mode, affecting clients that do not support WebAuth/SSO.
What is the CVSS score for CVE-2026-41070?
CVE-2026-41070 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N. EPSS: 0.4%.
Is CVE-2026-41070 actively exploited?
No confirmed active exploitation of CVE-2026-41070 as of 2026-05-30.
How do I remediate CVE-2026-41070?
Priority: IMMEDIATE.
What systems are affected by CVE-2026-41070?
CVE-2026-41070 affects: Client, Linux, Openvpn, Plugin.
Vulnerability Details
CVE IDCVE-2026-41070
BSIDBS-2026-GLOBAL-152408-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Published2026-05-08
Last Modified2026-05-13
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows. From version 1.26.3 to before version 1.27.3, when openvpn-auth-oauth2 is deployed in the experimental plugin mode (shared library loaded by OpenVPN via the plugin directive), clients that do not support WebAuth/SSO (e.g., the openvpn CLI on Linux) are incorrectly admitted to the VPN despite being denied by the authentication logic. The default management-interface mode is not affected because it does not use the OpenVPN plugin return-code mechanism. This issue has been patched in version 1.27.3.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can exploit this vulnerability by sending specially crafted requests to the OpenVPN server using the openvpn-auth-oauth2 plugin, potentially bypassing authentication for clients that do not support WebAuth/SSO.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Client —
Linux —
Openvpn —
Plugin —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 88 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash0be6cb9e72adb9de3c5573187dbe6ef0d4e2094b9837ca8b94a37b19b83a27ec407c8606695abb71232026b91faa7863943944ada9bf3f283ec888553ec6a56f
Related CVEs affecting Client
CVE-1999-0661 10.0 A system is running a version of software that was replaced with a Trojan Hor... CVE-2025-53624 10.0 The Docusaurus gists plugin adds a page to your Docusaurus instance, displayi... CVE-2025-6512 10.0 On a client with a non-admin user, a script can be integrated into a report. ... CVE-2026-23693 10.0 ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elemen... CVE-2026-40089 9.9 Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. Th...
View all Client CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →