Database/Control plane, storage & DevOps

Tailscale (Windows client): Local API bound to a TCP socket
CVSS 9.6CVE-2022-41924Control plane, storage & DevOpscurated
Impact
Local API bound to a TCP socket -> a malicious website reconfigures tailscaled and achieves RCE
Who can reach it
Network (remote)
What to do
Control-plane: force-update all operator clients
References
Related entries
- GitLab: Attacker can trigger a CI pipeline as another userCVE-2024-6385 · GitLabCritical
- AAP Controller: testing a Vault credential sends the controller pod's service account token to an attacker URLCVE-2026-12564 · Red Hat Ansible Automation Platform Controller (awx_plugins HashiCorp Vault credential plugin)Critical
- Termix: any authenticated user can read other users' stored SSH and sudo passwordsCVE-2026-53548 · Termix (GET /host/db/host/:id/password credential endpoint)Critical
- Progress LoadMaster (ADC): OS command injection in the APICVE-2026-8037 · Progress LoadMaster (ADC)Critical
- Vault Secrets Operator: tenant-controlled AppRole config reads operator pod files and exfiltrates themCVE-2026-8715 · HashiCorp Vault Secrets Operator (AppRole secretIDPath configuration)Critical
- Johnson Controls Metasys Application and Data Server (ADS) deployed with SQL Express: Command injection on the MetasysCVE-2025-26385 · Johnson Controls Metasys Application and Data Server (ADS) deployed with SQL ExpressCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.