TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access

Tailscale has released version 1.66.0 to patch a security vulnerability that could allow unauthorized root access via insecure argument handling in SSH. The flaw affected Linux-based exit nodes and subnet routers using default ACL configurations.
Why it matters
This is a critical security update for users of the Tailscale mesh VPN, as the vulnerability could potentially allow attackers to bypass network access controls.
Description : Insufficient inbound packet filtering in subnet routers and exit nodes
In Tailscale versions earlier than 1.66.0, exit nodes , subnet routers , and app connectors , could allow inbound connections to other tailnet nodes from their local area network (LAN). This vulnerability only affects Linux exit nodes, subnet routers, and app connectors in tailnets where ACLs allow "src": "*" , such as with default ACLs .
Tailscale version 1.66.0 fixes the vulnerability. Additionally, a server-side update changes the interpretation of "src": "*" to mitigate the issue specifically for exit nodes.
Special thanks to Hakan Ergan for reporting a similar concern that led us to discover this vulnerability.
This affected the following nodes using Tailscale version 1.65 or earlier:
Tailnets with custom ACLs that do not use "src": "*" or any other value that includes external IPs were not affected.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in