ZDI-CAN-30134: ZDI-26-386: Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-9773.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to the Unraid web management interface (Web UI). Block or limit access from the public Internet at the perimeter firewall or router; allow only trusted IP addresses or require access via a corporate VPN. Also close or filter the Unraid management ports on network ACLs to reduce exposure.
- Operational
Verify that authentication is enforced for the Unraid Web UI (no anonymous or guest access). Ensure administrative accounts use strong, unique passwords, disable or remove unused accounts, and rotate credentials for any accounts with Web UI access.