Products: 3
    Vulnerabilities: 7
    Known Exploited: 0
    1
    Critical Level Threats
    5
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-43917

    In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninstalling the product. Specifically, an administrator can insert a new file at the pathname of the removed pritunl-service file. This file then is executed by a LaunchDaemon as root.

    Last Modified: Apr 15, 2026
    Published: Apr 19, 2025

    CVE-2022-25372

    Pritunl Client through 1.2.3019.52 on Windows allows local privilege escalation, related to an ACL entry for CREATOR OWNER in platform_windows.go.

    Last Modified: Nov 21, 2024
    Published: Feb 20, 2022

    CVE-2020-27519

    Pritunl Client v1.2.2550.20 contains a local privilege escalation vulnerability in the pritunl-service component. The attack vector is: malicious openvpn config. A local attacker could leverage the log and log-append along with log injection to create or append to privileged script files and execute code as root/SYSTEM.

    Last Modified: Nov 21, 2024
    Published: Apr 30, 2021

    CVE-2020-25989

    Privilege escalation via arbitrary file write in pritunl electron client 1.0.1116.6 through v1.2.2550.20. Successful exploitation of the issue may allow an attacker to execute code on the effected system with root privileges.

    Last Modified: Nov 21, 2024
    Published: Nov 19, 2020

    CVE-2020-25200

    Pritunl 1.29.2145.25 allows attackers to enumerate valid VPN usernames via a series of /auth/session login attempts. Initially, the server will return error 401. However, if the username is valid, then after 20 login attempts, the server will start responding with error 400. Invalid usernames will receive error 401 indefinitely. Note: This has been disputed by the vendor as not a vulnerability. They argue that this is an intended design

    Last Modified: Nov 21, 2024
    Published: Oct 01, 2020
    Items Per Page
    Pritunl Vulnerabilities & Security CVEs | CVE-DB