{"id":"GHSA-246w-jgmq-88fg","summary":"openvpn-auth-oauth2 returns FUNC_SUCCESS on client-deny, allowing unauthenticated VPN access","details":"# Summary\n\nWhen `openvpn-auth-oauth2` is deployed in the **experimental plugin mode** (shared library loaded by OpenVPN via the `plugin` directive), clients that do not support WebAuth/SSO (e.g., the `openvpn` CLI on Linux) are incorrectly admitted to the VPN despite being denied by the authentication logic. **The default management-interface mode is not affected** because it does not use the OpenVPN plugin return-code mechanism.\n\n# Impact\n\n**Authentication bypass — any VPN client that does not advertise WebAuth/SSO support (`IV_SSO=webauth`) is granted full network access without completing OIDC authentication.**\n\nThis affects only deployments running the **experimental plugin mode** in versions 1.26.3 through 1.27.2. The default and recommended deployment via the management interface is **not affected**.\n\nAn unauthenticated attacker can connect to the OpenVPN server using any standard OpenVPN client that does not support webauth (e.g., the Linux `openvpn` CLI). The plugin correctly issues a `client-deny` command via the management interface, but returns `OPENVPN_PLUGIN_FUNC_SUCCESS` (status=0) to OpenVPN. Because the `auth_control_file` content is only consulted when the plugin returns `FUNC_DEFERRED`, OpenVPN interprets status=0 as \"authentication passed\" and admits the client — granting full access to the internal network behind the VPN.\n\n\n## Root Cause\n\nIn `lib/openvpn-auth-oauth2/openvpn/handle.go`, the `ClientAuthDeny` branch of `handleAuthUserPassVerify` wrote `\"0\"` (deny) to the `auth_control_file` but returned `OPENVPN_PLUGIN_FUNC_SUCCESS`. OpenVPN only reads the `auth_control_file` when the plugin returns `FUNC_DEFERRED`; a synchronous `FUNC_SUCCESS` return is treated as immediate approval regardless of file contents.\n\n**Before fix:**\n```go\ncase management.ClientAuthDeny:\n    // ... writes \"0\" to auth_control_file ...\n    if err := openVPNClient.WriteToAuthFile(\"0\"); err != nil {\n        // only returned ERROR on write failure\n        return c.OpenVPNPluginFuncError\n    }\n    return c.OpenVPNPluginFuncSuccess  // ← BUG: OpenVPN sees this as \"auth passed\"\n```\n\n**After fix (commit [`36f69a6`](https://github.com/jkroepke/openvpn-auth-oauth2/commit/36f69a6c67c1054da7cbfa04ced3f0555127c8f2)):**\n```go\ncase management.ClientAuthDeny:\n    // ... writes \"0\" to auth_control_file ...\n    if err := openVPNClient.WriteToAuthFile(\"0\"); err != nil {\n        logger.ErrorContext(p.ctx, \"write to auth file\", slog.Any(\"err\", err))\n    }\n    return c.OpenVPNPluginFuncError  // ← FIX: OpenVPN now correctly rejects the client\n```\n\n# Patches\n\nThis vulnerability is fixed in **v1.27.3**. Users of the experimental plugin mode should upgrade immediately.\n\n- **Fix commit:** [`36f69a6`](https://github.com/jkroepke/openvpn-auth-oauth2/commit/36f69a6c67c1054da7cbfa04ced3f0555127c8f2)\n- **Fix PR:** [#829](https://github.com/jkroepke/openvpn-auth-oauth2/pull/829)\n\n# Workarounds\n\n- **Switch to standalone management client mode** (the default, non-plugin deployment). This mode is not affected by the vulnerability because authentication decisions are communicated entirely through the management interface protocol, not through the plugin return code.\n- **Restrict VPN access at the network level** to only clients known to support WebAuth/SSO (e.g., OpenVPN Connect 3+), although this is difficult to enforce reliably and is not recommended as a sole mitigation.","aliases":["CVE-2026-41070","GO-2026-4963"],"modified":"2026-05-20T19:41:33.297760399Z","published":"2026-04-22T14:28:11Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-04-22T14:28:11Z","nvd_published_at":"2026-05-08T16:16:11Z","cwe_ids":["CWE-287"],"severity":"CRITICAL"},"references":[{"type":"WEB","url":"https://github.com/jkroepke/openvpn-auth-oauth2/security/advisories/GHSA-246w-jgmq-88fg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41070"},{"type":"WEB","url":"https://github.com/jkroepke/openvpn-auth-oauth2/pull/829"},{"type":"WEB","url":"https://github.com/jkroepke/openvpn-auth-oauth2/commit/36f69a6c67c1054da7cbfa04ced3f0555127c8f2"},{"type":"WEB","url":"https://github.com/OpenVPN/openvpn/blob/master/include/openvpn-plugin.h.in"},{"type":"WEB","url":"https://github.com/OpenVPN/openvpn3/blob/master/doc/webauth.md"},{"type":"PACKAGE","url":"https://github.com/jkroepke/openvpn-auth-oauth2"},{"type":"WEB","url":"https://github.com/jkroepke/openvpn-auth-oauth2/releases/tag/v1.27.3"}],"affected":[{"package":{"name":"github.com/jkroepke/openvpn-auth-oauth2","ecosystem":"Go","purl":"pkg:golang/github.com/jkroepke/openvpn-auth-oauth2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.26.3"},{"fixed":"1.27.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-246w-jgmq-88fg/GHSA-246w-jgmq-88fg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"}]}