Junglewise Threat Intelligence

CVE-2026-9773: Unraid Web Server command injection in ToggleState.php

CVE-2026-9773 · Severity: high · CVSS 8.8 · Published 2026-06-24

Vendors: Unraid.

Executive brief

A security vulnerability exists in Unraid, a popular operating system for managing home servers and network-attached storage. An authorized user can exploit a flaw in the web management interface to run unauthorized commands on the server. This could allow an attacker to gain full control over the system, potentially leading to data theft, service disruption, or the installation of malicious software.

Technical details

A command injection vulnerability exists in the Unraid web server within the ToggleState.php component. The flaw is caused by insufficient validation of user-supplied input before it is passed to a system call. A remote, authenticated attacker can exploit this by sending a specially crafted request to execute arbitrary OS commands with the privileges of the 'www-data' user. The vulnerability is addressed in Unraid OS version 7.3.0 stable.

Affected products

  • Unraid Unraid OS Versions prior to 7.3.0 stable

Timeline

  • 2026-04-22: disclosed: Vulnerability reported to vendor
  • 2026-06-24: advisory: Coordinated public release of advisory
  • 2026-06-24: patched: Fixed in version 7.3.0 stable

References

Related threats