Executive brief
A security vulnerability exists in Unraid, a popular operating system for managing home servers and network-attached storage. An authorized user can exploit a flaw in the web management interface to run unauthorized commands on the server. This could allow an attacker to gain full control over the system, potentially leading to data theft, service disruption, or the installation of malicious software.
Technical details
A command injection vulnerability exists in the Unraid web server within the ToggleState.php component. The flaw is caused by insufficient validation of user-supplied input before it is passed to a system call. A remote, authenticated attacker can exploit this by sending a specially crafted request to execute arbitrary OS commands with the privileges of the 'www-data' user. The vulnerability is addressed in Unraid OS version 7.3.0 stable.
Affected products
- Unraid Unraid OS Versions prior to 7.3.0 stable
Timeline
- 2026-04-22: disclosed: Vulnerability reported to vendor
- 2026-06-24: advisory: Coordinated public release of advisory
- 2026-06-24: patched: Fixed in version 7.3.0 stable