Bug 2516214 (CVE-2026-63650)

Summary: CVE-2026-63650 openvpn: mbedtls: OpenVPN: User misidentification via ignored X.509 identity field
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in OpenVPN when using mbedTLS. A remote authenticated user could be misidentified due to the software ignoring the configured X.509 username identity lookup field. This could lead to incorrect user authentication and potential security bypasses.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2517346, 2517347    
Bug Blocks:    

Description OSIDB Bzimport 2026-08-14 22:31:23 UTC
OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field