Tailscale SSH flaw allows unauthorized root access
Tailscale, the WireGuard‑based VPN service, has issued a new security bulletin after a critical vulnerability was identified in its software. The flaw, which allows an attacker to bypass authentication and gain unauthorized access to a user’s network, was discovered by a security researcher and reported to Tailscale through its bug‑bounty program. The company confirmed the issue, released a patch, and advised all users to upgrade to the latest version immediately.
The vulnerability affects all Tailscale installations that rely on the default authentication flow, including both the desktop and mobile clients as well as the web console. An attacker who can intercept traffic to a Tailscale node could exploit the flaw to execute arbitrary commands with elevated privileges. Tailscale’s patch, available in version 1.40.0 and later, tightens the authentication checks and removes the code path that previously allowed the bypass. The company has also updated its documentation to recommend best practices for securing the VPN environment.
Tailscale’s rapid response and transparent communication have been noted by the security community. The incident underscores the importance of continuous security testing for VPN products that handle sensitive network traffic. Users are encouraged to monitor the official bulletin page for any further updates and to apply the latest security patches as soon as they become available.