tac_plus (elttam 23 Sep): pre-auth format-string RCE (CVE-pending) + PSK oracle; patch Shrubbery F4.0.4.32
Australian research firm elttam (blog dated 23 September 2026) discloses a remote pre-authentication format-string vulnerability (CWE-134; CVE-pending) in tac_plus, the long-lived open-source TACACS+ daemon descended from Cisco's 1990s Developer's Kit. On an error path, attacker-controlled session.port is passed as the format string to report()/logging helpers, yielding code execution as the daemon user (root by default) after the shared secret is known. A separate pre-auth truncated-AUTHEN/START error-reply oracle lets an attacker offline-crack weak PSKs (wordlist demo), and a client-laundering path can place a format-string payload via an oversized username on a TACACS-speaking network device without knowing the key. Affected: Cisco original kit lineage, every Shrubbery release through F4.0.4.31 (Feb 2026), and the archived Facebook/Meta fork (F4.0.4.28-7fb — will not be fixed). Shrubbery published F4.0.4.32 on 21 September 2026 fixing both sinks (changelog: single-line CWE-134 note). Cisco confirmed no Cisco product affected. Disclosure took ~90 days (Meta out-of-scope for archived fork; Shrubbery reply from spam queue). No CVSS assigned yet (CVE-pending). Primary: elttam; vendor download: shrubbery.net/tac_plus.
- Product
- tac_plus TACACS+ daemon (Shrubbery Networks; Facebook/Meta archived fork; Cisco Developer's Kit lineage)
- Versions
- Affected: Shrubbery through F4.0.4.31 inclusive; Facebook fork F4.0.4.28-7fb (archived, unfixed). Fixed: Shrubbery F4.0.4.32 (21 Sep 2026). Cisco products: vendor states not affected.
- Exploited in Australia?
- unknown
- Patch to
- Upgrade tac_plus to Shrubbery F4.0.4.32 (or apply equivalent format-string hardening); replace Facebook-fork builds; segment TCP/49 to management NAS only; use a high-entropy shared secret (not wordlistable); inventory appliances whose embedded TACACS+ stack inherited this tree
Primary: elttam — ATT&CKing TACACS+ pre-auth RCE (23 Sep 2026) · Vendor: Shrubbery Networks — tac_plus F4.0.4.32 · elttam — PSK oracle + mitigation notes
