CVE-2026-9560: OS Command Injection
Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
OpenVPN Connect (macOS)from your environment.Uninstall OpenVPN Connect if it is not required
- Configuration
Disable the OpenVPN Connect background service to prevent local IPC-based privilege escalation
OpenVPN Connect (macOS) background service enabled = false - Compensating control
Restrict or harden access to the local IPC channel used by OpenVPN Connect (e.g., tighten IPC/socket filesystem permissions or limit which local users/processes can communicate with the service)
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9560?
CVE-2026-9560 has a critical severity rating of 9.4.
How do I fix CVE-2026-9560?
To fix CVE-2026-9560, update OpenVPN Connect to a version later than 3.8.1.
What type of vulnerability is CVE-2026-9560?
CVE-2026-9560 is a privilege escalation vulnerability due to OS command injection.
Can CVE-2026-9560 be exploited remotely?
No, CVE-2026-9560 requires local access to exploit the vulnerability.
What software is affected by CVE-2026-9560?
CVE-2026-9560 affects OpenVPN Connect versions 3.5.1 through 3.8.1 on macOS.