CVE-2020-5849
unraid
Published 16 Mar 2020 · updated 17 Jun 2026 · Analyzed
7.5 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Nov 2021, with a remediation deadline of 3 May 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Unraid 6.8.0 allows authentication bypass.
References
- packetstormsecurity.com/files/157275/Unraid-6.8.0-Authentication-Bypass-Arbitrary-Code-Execution.html · Exploit, Third Party Advisory, VDB Entry
- forums.unraid.net/forum/7-announcements/ · Release Notes, Vendor Advisory
- sysdream.com/news/lab/ · Third Party Advisory
- sysdream.com/news/lab/2020-02-06-cve-2020-5847-cve-2020-5849-unraid-6-8-0-unauthenticated-remote-code-execution-as-root/ · Broken Link, Exploit, Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-5849 · US Government Resource