CVE-2025-29266 is a critical authentication bypass vulnerability affecting Unraid 7.0.0 before 7.0.1, allowing remote attackers to gain root access to the WebGUI and web console without credentials. This high-severity flaw, rated 9.6 CVSS, occurs when a container is configured with Host networking mode and Tailscale enabled, presenting a significant risk of complete compromise (confidentiality, integrity, and availability). While no active exploitation, public exploit code, or significant community discussion has been observed, the ease of exploitation and severe impact warrant immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0.0, < 7.0.1CPE match | cpe:2.3:o:unraid:unraid:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 1.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.