CVE-2026-9772: Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability
Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid. Authentication is required to exploit this vulnerability.
The specific flaw exists within FileUpload.php. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the www-data user. Was ZDI-CAN-30116.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9772?
CVE-2026-9772 has a severity rating of high, with a score of 8.8.
What does CVE-2026-9772 exploit?
CVE-2026-9772 exploits a command injection vulnerability in the FileUpload.php component of the Unraid web server.
How do I fix CVE-2026-9772?
To fix CVE-2026-9772, it is recommended to update your Unraid software to the latest version provided by Lime Technology.
Who is affected by CVE-2026-9772?
CVE-2026-9772 affects installations of Unraid that utilize the FileUpload feature, requiring user authentication for exploitation.
What can attackers do with CVE-2026-9772?
Attackers can execute arbitrary code on affected installations of Unraid, potentially compromising the system.