CVE-2026-13122: Medium severity OpenVPN OpenVPN vulnerability
Last updated 10 July 2026
Other sources
OpenVPN version 2.6.0 through 2.6.20 and 2.7alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/openvpnto a version that resolves this vulnerability.Fixed in 2.6.14-0+deb12u2Fixed in 2.6.14-1+deb13u3Fixed in 2.7.5-1 - Upgrade
Upgrade
OpenVPNto a version that resolves this vulnerability.Fixed in 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 - Configuration
If external-auth is enabled, disable it or otherwise prevent the feature from handling authentication tokens until OpenVPN is upgraded to a non-vulnerable release.
OpenVPN external-auth = enabled/disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13122?
CVE-2026-13122 has a risk score of 35, indicating a moderate severity vulnerability.
How do I fix CVE-2026-13122?
To mitigate CVE-2026-13122, upgrade OpenVPN to version 2.6.21 or later, or disable the external-auth feature if it is not required.
What versions of OpenVPN are affected by CVE-2026-13122?
CVE-2026-13122 affects OpenVPN versions 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4.
What type of vulnerability is CVE-2026-13122?
CVE-2026-13122 is a denial of service vulnerability that can be triggered by a malformed authentication token.
What is the potential impact of CVE-2026-13122?
The potential impact of CVE-2026-13122 is a denial of service that can disrupt OpenVPN functionality for legitimate users.