CVE-2026-3839: Unraid Authentication Request Path Traversal Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of Unraid. Authentication is not required to exploit this vulnerability. The specific flaw exists within the auth-request.php file. The issue results from the lack of proper validation of a user-supplied path prior to using it in authentications. An attacker can leverage this vulnerability to bypass authentication on the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3839?
CVE-2026-3839 is classified as a critical vulnerability due to its capacity to allow remote attackers to bypass authentication.
How do I fix CVE-2026-3839?
To fix CVE-2026-3839, ensure that you update your Unraid software to the latest version provided by Limetech that addresses this vulnerability.
Who is affected by CVE-2026-3839?
CVE-2026-3839 affects installations of Unraid that have not implemented the necessary security updates.
What type of attack does CVE-2026-3839 facilitate?
CVE-2026-3839 facilitates unauthorized access by allowing attackers to bypass authentication mechanisms.
Is authentication required to exploit CVE-2026-3839?
No, authentication is not required to exploit CVE-2026-3839, making it particularly dangerous.