CVE-2020-5849
KEV PoC ×2largeAuthentication Bypass in Unraid 6.8.0 WebGUI (Chainable to Root RCE)
CISA: Unraid Authentication Bypass Vulnerability
Unraid 6.8.0, the webGUI of the popular self-hosted NAS operating system, contains an authentication bypass (CWE-697, an incorrect comparison in the session/token check) that allows a remote, unauthenticated attacker to gain admin access without valid credentials. It is triggered by sending crafted requests to the webGUI over the network — the CVSS vector (AV:N/AC:L/PR:N/UI:N) requires no privileges or user interaction, and the base 7.5 score reflects high-impact disclosure of management data, while the linked research shows the bypass chains with companion flaw CVE-2020-5847 for unauthenticated remote code execution as root. Any Unraid 6.8.0 deployment whose webGUI is reachable by untrusted users, especially ones exposed directly to the internet, is affected. Exploitation is confirmed in the wild: the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03, required action: apply vendor updates) and has a very high exploitation probability (EPSS 93.2%, 100th percentile), with public proof-of-concept exploits available. Ransomware involvement is listed as unknown by CISA.
What to do: Upgrade Unraid away from 6.8.0 to the vendor's patched release (6.8.1 or later contains the webGUI authentication fix), per CISA's required action to apply updates per vendor instructions. Restrict the webGUI (HTTP/HTTPS ports) behind a VPN or trusted network rather than exposing it directly to the internet, and check webGUI access logs for unauthenticated or anomalous logins indicating exploitation. After patching, rotate the root/admin password as a precaution.
| Unraid (NAS operating system webGUI) | 6.8.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unraid 6.8.0 allows authentication bypass.
- Affected
- Unraid Unraid
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- unraid
- Products
- unraid
- Weakness
- CWE-697
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.