CVE Feed

    Dashboard / CVE / CVE-2026-57999

    CVE-2026-57999

    luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows authenticated users to execute arbitrary commands as root. The vulnerability exists because user-controlled loginserver and loginserver_authkey parameters are improperly quoted within a double-quoted shell command, allowing shell substitutions like $() to be evaluated by the outer shell before argument processing.

    Published:Jun 29, 2026
    Last Modified:Jun 30, 2026
    EPS:Jun 29, 2026
    EPSS Score:0.01179
    CVSS Score:8.8

    Affected Products

    Vendor
    Openwrt
    Product
    Luci

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High