CVE-2026-2542

HIGH

Total VPN 0.5.29.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A weakness has been identified in Total VPN 0.5.29.0 on Windows. Affected by this vulnerability is an unknown functionality of the file C:\Program Files\Total VPN\win-service.exe. Executing a manipulation can lead to unquoted search path. It is possible to launch the attack on the local host. This attack is characterized by high complexity. The exploitation appears to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry
https://vuldb.com/?id.346127
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.346127
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.749365

Scores

CVSS v3 7.0
EPSS 0.0016
EPSS Percentile 5.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-426 CWE-428
Status published
Products (1)
n/a/Total VPN 0.5.29.0
Published Feb 16, 2026
Tracked Since Feb 18, 2026