ZDI-26-172: Unraid Authentication Request Path Traversal Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of Unraid. Authentication is not required to exploit this vulnerability. The specific flaw exists within the auth-request.php file. The issue results from the lack of proper validation of a user-supplied path prior to using it in authentications. An attacker can leverage this vulnerability to bypass authentication on the system.
Other sources
This vulnerability allows remote attackers to bypass authentication on affected installations of Unraid. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.3. The following CVEs are assigned: CVE-2026-3839.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-172?
The severity of ZDI-26-172 is classified as high with a score of 7.3.
How do I fix ZDI-26-172?
To fix ZDI-26-172, ensure you update your Unraid installation to the latest version that addresses this vulnerability.
What type of vulnerability is ZDI-26-172?
ZDI-26-172 is an authentication bypass vulnerability which allows remote attackers to access systems without proper authentication.
Which file is affected by ZDI-26-172?
The specific file affected by ZDI-26-172 is the auth-request.php file in the Unraid software.
Can ZDI-26-172 be exploited remotely?
Yes, ZDI-26-172 can be exploited remotely as it does not require authentication to carry out the attack.