ZDI-CAN-30116: ZDI-26-385: Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-9772.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Require and enforce authentication for the Unraid Web Server and its file-upload functionality; ensure no unauthenticated access is permitted to the management/web upload interface.
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-30116?
The severity of ZDI-CAN-30116 is rated at 8.8 on the CVSS scale.
How do I fix ZDI-CAN-30116?
To fix ZDI-CAN-30116, update your Unraid installation to the latest version that addresses this vulnerability.
What type of vulnerability is ZDI-CAN-30116?
ZDI-CAN-30116 is a command injection remote code execution vulnerability in the Unraid web server.
Who is impacted by ZDI-CAN-30116?
Users of affected Unraid installations that allow file uploads and require authentication are impacted by ZDI-CAN-30116.
What is required to exploit ZDI-CAN-30116?
Exploitation of ZDI-CAN-30116 requires authentication to the Unraid web interface.