{"id":"DEBIAN-CVE-2026-41070","details":"openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows. From version 1.26.3 to before version 1.27.3, when openvpn-auth-oauth2 is deployed in the experimental plugin mode (shared library loaded by OpenVPN via the plugin directive), clients that do not support WebAuth/SSO (e.g., the openvpn CLI on Linux) are incorrectly admitted to the VPN despite being denied by the authentication logic. The default management-interface mode is not affected because it does not use the OpenVPN plugin return-code mechanism. This issue has been patched in version 1.27.3.","modified":"2026-09-29T13:03:53.696389862Z","published":"2026-05-08T16:16:11.030Z","upstream":["CVE-2026-41070"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-41070"}],"affected":[{"package":{"name":"openvpn-auth-oauth2","ecosystem":"Debian:14","purl":"pkg:deb/debian/openvpn-auth-oauth2?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.27.3-1"}]}],"versions":["1.26.2+dfsg-1","1.26.4+dfsg-1","1.26.4+dfsg-2","1.26.4+dfsg-3","1.26.4+dfsg-4","1.26.4+dfsg-5","1.26.4+dfsg-6","1.27.0-1","1.27.0-2","1.27.1-1","1.27.2-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-41070.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"}]}