CVE-2025-29266: Critical severity unraid vulnerability
Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication if a container is running in Host networking mode with Use Tailscale enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29266?
CVE-2025-29266 is considered a critical vulnerability as it allows unauthorized remote access to the Unraid WebGUI and web console.
How do I fix CVE-2025-29266?
To fix CVE-2025-29266, upgrade your Unraid installation to version 7.0.1 or later.
Who is affected by CVE-2025-29266?
CVE-2025-29266 affects Unraid versions prior to 7.0.1 when containers are running in Host networking mode with Use Tailscale enabled.
What are the potential risks of CVE-2025-29266?
The risks of CVE-2025-29266 include unauthorized access to sensitive data and the ability to modify system settings without authentication.
Is authentication required in CVE-2025-29266?
No, CVE-2025-29266 allows remote users to access the system as root without any authentication if the specified conditions are met.