CVE-2026-31893 Details
Description
Tunnelblick is an open source graphic user interface for OpenVPN on macOS. In versions 3.3beta26 through 9.0beta01, any local user can read arbitrary root-owned files by exploiting a symlink following vulnerability in tunnelblick-helper, reachable through the world-accessible tunnelblickd Unix socket. The socket is configured with mode 0666, allowing any local user to connect. No authorization check is performed on the connecting client. The tunnelblick-helper process constructs a path to config.ovpn inside a user-controlled .tblk directory and reads it as root without symlink validation. An attacker can create a .tblk configuration with a symlinked config.ovpn pointing to any file and request tunnelblickd to read it. This issue has been fixed in versions 9.0beta02.
A symlink following vulnerability has been identified in Tunnelblick, an open-source graphical user interface for OpenVPN on macOS. This vulnerability exists in versions 3.3beta26 prior to 9.0beta01. Any local user can exploit this issue to read arbitrary root-owned files by taking advantage of the vulnerability in the 'tunnelblick-helper' component. The flaw is accessible through the world-readable 'tunnelblickd' Unix socket, which lacks authorization checks for connecting clients. The 'tunnelblick-helper' process reads a user-controlled 'config.ovpn' file as root, without validating symlinks, allowing attackers to create a configuration that points to sensitive files.
Users can update to Tunnelblick version 9.0beta02 or 8.0.1, both of which include the necessary fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Tunnelblick/Tunnelblick/security/advisories/GHSA-927j-vcjf-hq69 | CISA-ADP | ExploitVendor Advisory |
| https://github.com/Tunnelblick/Tunnelblick/releases/tag/v9.0beta02 | [email protected] | ProductRelease Notes |
| https://github.com/Tunnelblick/Tunnelblick/security/advisories/GHSA-927j-vcjf-hq69 | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-61 | UNIX Symbolic Link (Symlink) Following | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| tunnelblick tunnelblick | >= 3.5.3, < 8.0.1 3.3 beta26 8.1 beta01 8.1 beta02 8.1 beta03 9.0 beta01 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 25, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | Initial Analysis | [email protected] |
| May 5, 2026 | New CVE Received | [email protected] |
| May 5, 2026 | CVE Modified | CISA-ADP |