Junglewise Threat Intelligence

CVE-2026-9772: Unraid OS command injection in FileUpload.php

CVE-2026-9772 · Severity: high · CVSS 8.8 · Published 2026-06-24

Vendors: Unraid.

Executive brief

Unraid, a popular operating system for managing home servers and network-attached storage (NAS), contains a security flaw in its web-based management interface. An authorized user can exploit this weakness to run unauthorized commands on the server. This could lead to a total compromise of the system, allowing an attacker to access, modify, or delete stored data and disrupt server operations.

Technical details

An OS command injection vulnerability exists in the FileUpload.php component of the Unraid web server. The flaw stems from insufficient validation of user-supplied strings before they are passed to a system call. A remote attacker with low-privileged authentication can exploit this by sending a specially crafted request to the web interface. Successful exploitation allows for arbitrary code execution in the context of the www-data user. The issue is resolved in Unraid OS version 7.3.0 stable.

Affected products

  • Unraid Unraid OS versions prior to 7.3.0 stable

Timeline

  • 2026-04-22: disclosed: Vulnerability reported to vendor
  • 2026-06-24: advisory: Coordinated public release of advisory
  • 2026-06-24: patched: Fixed in version 7.3.0 stable

References

Related threats