ZeroHour

CVE-2020-5849

KEV PoC ×2large

Authentication Bypass in Unraid 6.8.0 WebGUI (Chainable to Root RCE)

CISA: Unraid Authentication Bypass Vulnerability

CVSS 3.1
7.5 high
EPSS
93%p100
Published
()
KEV added
AI analysis

Unraid 6.8.0, the webGUI of the popular self-hosted NAS operating system, contains an authentication bypass (CWE-697, an incorrect comparison in the session/token check) that allows a remote, unauthenticated attacker to gain admin access without valid credentials. It is triggered by sending crafted requests to the webGUI over the network — the CVSS vector (AV:N/AC:L/PR:N/UI:N) requires no privileges or user interaction, and the base 7.5 score reflects high-impact disclosure of management data, while the linked research shows the bypass chains with companion flaw CVE-2020-5847 for unauthenticated remote code execution as root. Any Unraid 6.8.0 deployment whose webGUI is reachable by untrusted users, especially ones exposed directly to the internet, is affected. Exploitation is confirmed in the wild: the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03, required action: apply vendor updates) and has a very high exploitation probability (EPSS 93.2%, 100th percentile), with public proof-of-concept exploits available. Ransomware involvement is listed as unknown by CISA.

What to do: Upgrade Unraid away from 6.8.0 to the vendor's patched release (6.8.1 or later contains the webGUI authentication fix), per CISA's required action to apply updates per vendor instructions. Restrict the webGUI (HTTP/HTTPS ports) behind a VPN or trusted network rather than exposing it directly to the internet, and check webGUI access logs for unauthenticated or anomalous logins indicating exploitation. After patching, rotate the root/admin password as a precaution.

Affected
Unraid (NAS operating system webGUI)6.8.0
Estimated exposure
large≈100,000+ Unraid servers in the plausibly affected installed base (order 10^5); internet-exposed webGUIs likely in the thousands to tens of thousands — Unraid's paid-license installed base was on the order of hundreds of thousands of servers (vendor sales/community statistics) and 6.8.0 was the current release at disclosure, though only the subset with an internet-exposed webGUI — likely…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unraid 6.8.0 allows authentication bypass.

CISA Known Exploited Vulnerability
Affected
Unraid Unraid
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
unraid
Products
unraid
Weakness
CWE-697
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.