VYPR
Medium severity6.4NVD Advisory· Published Oct 27, 2025· Updated Apr 15, 2026

CVE-2025-50055

CVE-2025-50055

Description

Cross-site scripting (XSS) vulnerability in the SAML Authentication module in OpenVPN Access Server version 2.14.0 through 2.14.3 allows configured remote SAML Assertion Consumer Service (ACS) endpoint servers to inject arbitrary web script or HTML via the RelayState parameter

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-site scripting vulnerability in OpenVPN Access Server SAML module allows remote SAML ACS servers to inject arbitrary script via RelayState parameter.

The SAML Authentication module in OpenVPN Access Server versions 2.14.0 through 2.14.3 contains a cross-site scripting (XSS) vulnerability. The issue lies in the handling of the RelayState parameter within the SAML Assertion Consumer Service (ACS) endpoint. An attacker who controls a configured remote SAML ACS endpoint server can inject arbitrary web script or HTML via this parameter.

Exploitation requires the attacker to be a configured remote SAML ACS endpoint server, meaning they must have control over a SAML identity provider or ACS endpoint trusted by the OpenVPN Access Server. The attacker can craft a malicious RelayState value that, when processed by the ACS endpoint, executes script in the context of the admin web UI or user session.

Successful exploitation could allow the attacker to perform actions on behalf of an authenticated administrator or user, such as stealing session cookies, redirecting to malicious sites, or modifying settings. The CVSS score of 6.4 indicates medium severity, likely due to the requirement of a configured remote endpoint.

The vulnerability is fixed in OpenVPN Access Server versions beyond 2.14.3. Users should upgrade to the latest version as recommended in the release notes [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.