CVE-2026-57999 Details
Description
luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows authenticated users to execute arbitrary commands as root. The vulnerability exists because user-controlled loginserver and loginserver_authkey parameters are improperly quoted within a double-quoted shell command, allowing shell substitutions like $() to be evaluated by the outer shell before argument processing.
A command injection vulnerability has been identified in the 'luci-app-tailscale-community' package for OpenWrt. This vulnerability exists in the 'tailscale.do_login' RPC method, where user-controlled parameters are improperly quoted, allowing authenticated users to execute arbitrary commands as root. The issue arises because the 'loginserver' and 'loginserver_authkey' parameters are embedded within a double-quoted shell command, enabling shell substitutions to be evaluated by the outer shell before the arguments are processed. The vulnerability affects all versions of 'luci-app-tailscale-community' up to and including the version available in the OpenWrt master branch.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 29, 2026CISA-ADP
Assessed Jun 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/openwrt/luci/security/advisories/GHSA-xwc5-mx58-rh35 | CISA-ADP | AdvisoryExploitTechnical AnalysisVendor |
| https://github.com/openwrt/luci/security/advisories/GHSA-xwc5-mx58-rh35 | [email protected] | AdvisoryExploitTechnical AnalysisVendor |
| https://www.vulncheck.com/advisories/luci-app-tailscale-community-command-injection-via-tailscale-do-login-rpc | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openwrt luci-app-tailscale-community | master |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 30, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | CVE Modified | [email protected] |
| Jun 29, 2026 | New CVE Received | [email protected] |
Volerion