CVE-2026-41070Disclosure

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (6 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows. From version 1.26.3 to before version 1.27.3, when openvpn-auth-oauth2 is deployed in the experimental plugin mode (shared library loaded by OpenVPN via the plugin directive), clients that do not support WebAuth/SSO (e.g., the openvpn CLI on Linux) are incorrectly admitted to the VPN despite being denied by the authentication logic. The default management-interface mode is not affected because it does not use the OpenVPN plugin return-code mechanism. This issue has been patched in version 1.27.3.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

RISING

Threat summary

  • Public PoC is present in monitored signal
  • 11 mentions across 5 observed days
  • Momentum state: rising

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 8 signals
  • Disclosure: 8 classified signals
  • General: 3 classified signals
  • Peaked at 6 mentions on most recent observed day (2026-05-12)
  • 11 total mentions across 5 days

Deep dive

Activity timeline11 mentions / 5d
02356Mentions · 2026-04-23: 1Mentions · 2026-05-08: 2Mentions · 2026-05-09: 1Mentions · 2026-05-10: 1Mentions · 2026-05-12: 6PoC Mentioned / Linked · 2026-05-10: 1Technical Details · 2026-04-23: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-09: 1Technical Details · 2026-05-12: 504-2305-0805-0905-1005-12
Signal classification2 categories
Disclosure
872.7%
General
327.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-231
Disclosure1
2026-05-082
Disclosure2
2026-05-091
Disclosure1
2026-05-101
Disclosure1
2026-05-126
Disclosure3General3
Full discourse11 posts
  • Lyrie.ai@lyrie_ai
    General

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-41070 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The advisory announces a critical vulnerability (CVE-2026-41070) with a 10 CVSS score, but no proof‑of‑concept, exploit, or patch information is provided.

    1000036
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    References CVE: CVE-2026-41070 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces CVE-2026-41070 as a critical vulnerability with CVSS 10 but lacks information on exploitation evidence, PoC, or remediation.

    1000032
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-41070 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows.

    Post summary

    The post announces CVE-2026-41070 with a CVSS score of 10 (critical), but provides no PoC, exploit, patch, or active exploitation details.

    1000038
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-41070 (CVSS 10) — multiple products. CVE: CVE-2026-41070 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The advisory announces CVE-2026-41070 as a critical vulnerability with a CVSS score of 10, but does not provide any exploitation details or remediation guidance.

    1000035
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-41070-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text briefly references a CVE via a URL and hashtags but does not provide concrete details, links to proof of concept, exploit code, or evidence of active exploitation.

    0000021
    210 followersView on X
  • Vignesh_Pravin@VigneshVic23698
    Disclosure

    CVE-2026-41070: OpenVPN Plugin Flaw Allows Unauthenticated Access https://thecybrdef.com/cve-2026-41070-openvpn-plugin-unauthenticated-access/ #OpenVpnPlugins #Cybersecurityplugins #Cybersecurity

    Post summary

    The brief announcement highlights CVE‑2026‑41070, a plugin flaw in OpenVPN that permits unauthenticated access, and directs readers to an external link for further details.

    0000038
    2 followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    CVE-2026-41070: OpenVPN Plugin Flaw Allows Unauthenticated Access https://thecybrdef.com/cve-2026-41070-openvpn-plugin-unauthenticated-access/ #OpenVpnPlugins #Cybersecurityplugins #Cybersecurity

    Post summary

    The post announces CVE‑2026‑41070, an unauthenticated access flaw in OpenVPN plugins, and links to a write‑up, but it provides no concrete exploit details, mitigation, or evidence of active exploitation.

    0000033
    9 followersView on X
  • selva@SelvaKtm2
    Disclosure

    CVE-2026-41070: OpenVPN Plugin Flaw Allows Unauthenticated Access https://thecybrdef.com/cve-2026-41070-openvpn-plugin-unauthenticated-access/ #OpenVpnPlugins #Cybersecurityplugins #Cybersecurity https://t.co/rSSj3Tnfcg

    Post summary

    The tweet announces CVE‑2026‑41070, noting a flaw in OpenVPN plugins that permits unauthenticated access and links to an article for details.

    0000020
    5 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41070 Authentication Bypass in openvpn-auth-oauth2 Plugin Mode Versions 1.26.3-1.27.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41070

    Post summary

    The post announces CVE-2026-41070, an authentication bypass in openvpn‑auth‑oauth2 plugin mode for versions 1.26.3‑1.27.2, without providing PoC, exploit code, active exploitation, or patch information.

    0000083
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41070 openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows. From version 1.26.3 to before … https://www.cve.org/CVERecord?id=CVE-2026-41070

    Post summary

    The message references CVE-2026-41070 as an OpenVPN OIDC SSO plugin issue, providing no details on exploitation, patches, or severity.

    0000087
    57.5K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    The `openvpn-auth-oauth2` module is affected by `CVE-2026-41070`, allowing unauthenticated VPN access due to incorrect client-deny handling. Review configurations and monitor for updates. #OpenVPN #OAuth2 #infosec https://www.pulsepatch.io/posts/cve-2026-41070-openvpn-auth-oauth2-unauthenticated-access

    Post summary

    A vulnerability (CVE-2026-41070) in openvpn-auth-oauth2 that permits unauthenticated VPN access is disclosed, with no PoC, exploit, or patch mentioned.

    0000069
    12 followersView on X

Explore more