Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 07 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Memory Corruption and Sensitive Information Disclosure via Crafted NRPT Inputs in Windows Interactive Service | |
| First Time appeared |
Openvpn
Openvpn openvpn |
|
| Vendors & Products |
Openvpn
Openvpn openvpn |
Mon, 07 Sep 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs. | |
| Weaknesses | CWE-131 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: OpenVPN
Published:
Updated: 2026-09-07T07:28:14.135Z
Reserved: 2026-08-26T14:41:20.459Z
Link: CVE-2026-78221
No data.
Status : Received
Published: 2026-09-07T08:17:12.813
Modified: 2026-09-07T08:17:12.813
Link: CVE-2026-78221
No data.
OpenCVE Enrichment
Updated: 2026-09-07T08:30:14Z
-
CWE-131
Incorrect Calculation of Buffer Size