CVE-2025-56798: CSRF
Published Aug 26, 2026
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows remote attackers to escalate privileges via the Unraid authentication cookie's lax same-site policy.
Affected Software
1 affected component
Lime Technology Unraid OS<=6.12.14
Event History
Aug 26, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
Description
Frequently Asked Questions
1
What must an attacker have to exploit this issue?
The attacker needs to induce a victim’s browser to send a cross-site request while the victim is authenticated to Unraid OS. The issue relies on the Unraid authentication cookie using a lax same-site policy.
2
Which deployments are affected?
Unraid OS version 6.12.14 and earlier are identified as affected. The provided information does not state any additional configuration requirement.
3
What is the potential impact if exploitation succeeds?
A remote attacker can escalate privileges through CSRF using the victim’s Unraid authentication cookie.