Skip to main content
CRITICAL

CVE-2026-59800

CVSS v3

9.8

CRITICAL

EPSS Score

1.4 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-install endpoint (this route is not covered by the dashboard middleware matcher, so no authorization check is applied). The sudoPassword field from the request body is written to the stdin of a 'sudo -S sh' child process. When sudo does not prompt for a password (the process runs as root, NOPASSWD is configured, or a recent sudo timestamp cache exists), the sudoPassword value is

Technical details

CVSS v3 Vector
3.1
Published
2026-07-07
Last Modified
2026-07-07

Frequently asked questions

What is CVE-2026-59800?

9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-install endpoint (this route is not covered by the dashboard middleware matcher, so no authorization check is applied). The sudoPassword field from the request body is written to the stdin of a 'sudo -S sh' child process. When sudo does not prompt for a password (the process runs as root, NOPASSWD is configured, or a recent sudo timestamp cache exists), the sudoPassword value is

Is CVE-2026-59800 actively exploited?

Active exploitation of CVE-2026-59800 has not been confirmed. The EPSS score is 1.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-59800?

CVE-2026-59800 has a CVSS v3 base score of 9.8 (CRITICAL severity), with vector string 3.1.

Is CVE-2026-59800 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key