Unraid is a specialized operating system for personal and small-business network-attached storage and compute servers, with its vulnerability profile concentrated in the core Unraid system product. The durable signal centers on access-control and path-handling issues, including path traversal and comparison logic flaws, which reflect the product's need to manage file permissions and directory isolation in a multi-user storage context. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unraid over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-5847CRITICAL Unraid through 6.8.0 allows Remote Code Execution. | Mar 16, 2020 | 9.8 | 98 | YES | YES |
CVE-2020-5849HIGH Unraid 6.8.0 allows authentication bypass. | Mar 16, 2020 | 7.5 | 97 | YES | YES |
CVE-2026-9772HIGH Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations o | Jun 24, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-9773HIGH Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | Jun 24, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-3838HIGH Unraid Update Request Path Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid. | Mar 13, 2026 | 8.8 | 31 | NO | NO |
CVE-2025-29266CRITICAL Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication if a container is running in Host networking mode with Use | Mar 31, 2025 | 9.6 | 27 | NO | NO |
CVE-2026-3839HIGH Unraid Authentication Request Path Traversal Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of U | Mar 16, 2026 | 7.3 | 22 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unraid.
Media articles that mention a CVE ID that affects a product developed by Unraid — matched by CVE ID, not by vendor name.