CVE-2026-9772
Beschrijving NL
Unraid Webserver FileUpload Command Injection Remote Code Execution Vulnerability. Met dit beveiligingslek kunnen externe aanvallers willekeurige code uitvoeren op getroffen installaties van Unraid. Authenticatie is vereist om deze kwetsbaarheid te misbruiken. De specifieke fout bestaat binnen FileUpload.php. Het probleem is het gevolg van het ontbreken van de juiste validatie van een door de gebruiker geleverde tekenreeks voordat deze wordt gebruikt om een systeemaanroep uit te voeren. Een aanvaller kan deze kwetsbaarheid gebruiken om code uit te voeren in de context van de www-data gebruiker. Was ZDI-CAN-30116.
Origineel (Engels) tonen
Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid. Authentication is required to exploit this vulnerability.
The specific flaw exists within FileUpload.php. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the www-data user. Was ZDI-CAN-30116.