CVE-2026-41070

Publication date 8 May 2026

Last updated 13 May 2026


Ubuntu priority

Cvss 3 Severity Score

10.0 · Critical

Score breakdown

Description

openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows. From version 1.26.3 to before version 1.27.3, when openvpn-auth-oauth2 is deployed in the experimental plugin mode (shared library loaded by OpenVPN via the plugin directive), clients that do not support WebAuth/SSO (e.g., the openvpn CLI on Linux) are incorrectly admitted to the VPN despite being denied by the authentication logic. The default management-interface mode is not affected because it does not use the OpenVPN plugin return-code mechanism. This issue has been patched in version 1.27.3.

Status

Package Ubuntu Release Status
openvpn-auth-oauth2 26.04 LTS resolute
Needs evaluation
25.10 questing Not in release
24.04 LTS noble Not in release
22.04 LTS jammy Not in release

Severity score breakdown

CVSS version: CVSS v3.0

Base score 10.0 · Critical

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N


Access our resources on patching vulnerabilities