Pritunl provides a focused VPN and network access platform centered around its client and server applications, where the exposure concentrates in the Pritunl Client across desktop and electron-based deployments. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, recalling through weakness classes including improper privilege management, path traversal, link-following flaws, cryptographic signature validation issues, and observable discrepancies that reflect the trust and file-access control demands of client-side VPN software. Defenders should treat Pritunl Client updates as a priority where it is deployed for remote access; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pritunl over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25200MEDIUM Pritunl 1.29.2145.25 allows attackers to enumerate valid VPN usernames via a series of /auth/session login attempts. Initially, the server will return error 401. However, if the us | Oct 1, 2020 | 5.3 | 31 | NO | YES |
CVE-2016-7063CRITICAL A flaw was found in pritunl-client before version 1.0.1116.6. Arbitrary write to user specified path may lead to privilege escalation. | Jul 21, 2020 | 9.8 | 31 | NO | NO |
CVE-2022-25372HIGH Pritunl Client through 1.2.3019.52 on Windows allows local privilege escalation, related to an ACL entry for CREATOR OWNER in platform_windows.go. | Feb 20, 2022 | 7.8 | 25 | NO | NO |
CVE-2016-7064HIGH A flaw was found in pritunl-client before version 1.0.1116.6. A lack of signature verification leads to sensitive information leakage | Jul 21, 2020 | 7.5 | 25 | NO | NO |
CVE-2020-27519HIGH Pritunl Client v1.2.2550.20 contains a local privilege escalation vulnerability in the pritunl-service component. The attack vector is: malicious openvpn config. A local attacker c | Apr 30, 2021 | 7.8 | 23 | NO | NO |
CVE-2025-43917HIGH In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninstalling the product. Specifically, an administrator can inser | Apr 19, 2025 | 8.2 | 20 | NO | NO |
CVE-2020-25989HIGH Privilege escalation via arbitrary file write in pritunl electron client 1.0.1116.6 through v1.2.2550.20. Successful exploitation of the issue may allow an attacker to execute code | Nov 19, 2020 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pritunl.
Media articles that mention a CVE ID that affects a product developed by Pritunl — matched by CVE ID, not by vendor name.