ZDI-CAN-28912: ZDI-26-172: Unraid Authentication Request Path Traversal Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of Unraid. Authentication is not required to exploit this vulnerability. The specific flaw exists within the auth-request.php file. The issue results from the lack of proper validation of a user-supplied path prior to using it in authentications. An attacker can leverage this vulnerability to bypass authentication on the system.
Other sources
This vulnerability allows remote attackers to bypass authentication on affected installations of Unraid. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.3. The following CVEs are assigned: CVE-2026-3839.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28912?
The severity of ZDI-CAN-28912 is high with a CVSS score of 7.3.
How do I fix ZDI-CAN-28912?
To fix ZDI-CAN-28912, ensure that you update your Unraid installation to the latest patched version provided by the vendor.
What types of systems are affected by ZDI-CAN-28912?
ZDI-CAN-28912 affects installations of Unraid that have vulnerable configurations.
What impact does ZDI-CAN-28912 have on affected systems?
ZDI-CAN-28912 allows attackers to bypass authentication, potentially leading to unauthorized access to the system.
Is authentication required to exploit ZDI-CAN-28912?
No, authentication is not required to exploit ZDI-CAN-28912, making it particularly dangerous.