Vulnerabilities
6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-9773 +1 in the same advisory: …9772 | Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability. Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid. Authentication is required to exploit this vulnerability. The specific flaw exists within ToggleState.php. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the www-data user. Was ZDI-CAN-30134. NVD description · AI analysis pending | 8.8 | 2% |
| — | ||
| CVE-2026-3838 +1 in the same advisory: …3839 | Unraid Update Request Path Traversal Remote Code Execution Vulnerability. Unraid Update Request Path Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid. Authentication is required to exploit this vulnerability. The specific flaw exists within the update.php file. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-28951. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2020-5847 +1 in the same advisory: …5849 | Unauthenticated Remote Code Execution as Root in Unraid Through 6.8.0 Unraid versions through 6.8.0 are vulnerable to unauthenticated remote code execution: an attacker with network access to the server's web management interface can bypass authentication and execute arbitrary code with root privileges. The attack requires no credentials, special conditions, or user interaction (CVSS 3.1: AV:N/AC:L/PR:N/UI:N), so any internet-exposed or otherwise reachable Unraid server is directly exploitable. Successful exploitation gives an attacker full root-level control of the server, enabling data theft, malware or ransomware deployment, and persistence on the host. All Unraid deployments up to and including 6.8.0 are affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), public proof-of-concept exploits have been available since February 2020, and EPSS assigns a ~96% probability of exploitation in the next 30 days; ransomware-specific use is currently unknown. Do: Upgrade all Unraid servers to a release newer than 6.8.0 per vendor instructions, as required by the CISA KEV catalog. Until patched, restrict the Unraid web management interface to trusted networks (VPN or firewall rules) and do not expose it directly to the internet. Because exploitation yields root access, review patched-but-previously-exposed servers for signs of compromise such as unexpected processes, new user accounts or cron entries, and unfamiliar outbound connections. | 9.8 group max | 96% | KEV PoC ×2 |
| largetens of thousands of internet-exposed Unraid servers; hundreds of thousands of total installations |