Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication if a container is running in Host networking mode with Use Tailscale enabled.
The vulnerability classified as CWE-289 (Authentication Bypass by Alternate Name) occurs when the WebGUI authentication mechanism is bypassed when two conditions are met simultaneously: the container runs in Host networking mode and Tailscale integration is enabled. In such a configuration, network traffic directed to the Unraid web interface does not go through standard user identity verification, resulting in root access being granted to every user within network range.
The attacker gains full, unauthorized access to the Unraid WebGUI administrative panel and web console with root privileges, allowing complete takeover of the server, data modification, malicious software installation, and access to all system resources.
Update Unraid to version 7.0.1 or later, in which the vulnerability has been removed. Patch details are available in the official release notes at https://docs.unraid.net/unraid-os/release-notes/7.0.1/. Until the update is applied, it is recommended to disable the Use Tailscale option in the configuration of containers running in Host networking mode.
Unraid version 7.0.0 (before 7.0.1), when at least one container runs in Host networking mode with the Use Tailscale option enabled.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H