OS Command Injection in OpenVPN Server - CVE-2026-84256
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause command-line misbehavior.
The vulnerability exists due to improper neutralization of special characters in CreateProcess() command-line quoting when processing characters that are special to cmd.exe. A remote attacker can provide specially crafted command-line content to cause command-line misbehavior.
Exploitation requires a validation script and a rogue CA.