CVE-2026-9560 is a local privilege escalation vulnerability in OpenVPN Connect for macOS affecting versions 3.5.1 through 3.8.1. The flaw resides in the application's privileged background service or helper component and is classified as an OS command injection issue. A local attacker can interact with the service over a local IPC channel and inject arbitrary operating system commands that are executed with elevated privileges. Because the vulnerable component runs with high privileges to manage VPN functionality, successful exploitation can result in command execution as root. The issue does not require user interaction once the attacker has local access to the affected system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single standalone Python exploit, CVE-2026-9560.py, targeting a local privilege escalation condition in OpenVPN Connect's ovpnhelper component on Linux. The script is not part of a larger framework and is fully self-contained. Its core logic is organized into four functions: inject(), which crafts an HTTP-like POST request to /dpc-request and sends JSON over the UNIX socket /var/run/ovpnhelper_service.sock; build_revshell(), which generates a base64-encoded Python reverse shell payload; interactive_shell(), which provides a raw TTY-style interactive session; and main(), which orchestrates socket discovery, listener setup, payload injection, and shell handling. The exploit capability is command injection through the JSON field user_id in the dpc_request object. The injected command writes a base64-decoded Python script to /tmp/.r.py, executes it with python3, and removes the file afterward. That payload forks into the background, connects back to a listener bound on 127.0.0.1 using an ephemeral port chosen at runtime, duplicates the socket onto standard streams, and spawns /bin/bash. If the vulnerable service executes the injected command with elevated privileges, the callback yields an interactive root shell. There are no external network indicators or remote C2 endpoints; all communication is local. The exploit uses a UNIX domain socket for the vulnerable service and loopback TCP for the shell callback. Because the payload is hardcoded but functional, the exploit is best classified as OPERATIONAL rather than a simple proof of concept.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical local privilege escalation vulnerability in OpenVPN Connect for macOS that allows a local attacker to inject and execute arbitrary OS commands as root via the privileged helper component over a local IPC channel.
A local privilege escalation vulnerability in the background service of OpenVPN Connect on macOS that allows arbitrary command execution with elevated privileges via a local IPC channel.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.