CRITICAL🇵🇱 Wersja polska

CVE-2025-29266

CVSS 9.6v3.1pub. 2025-03-31upd. 2026-04-15

Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication if a container is running in Host networking mode with Use Tailscale enabled.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-289 (Authentication Bypass by Alternate Name) occurs when the WebGUI authentication mechanism is bypassed when two conditions are met simultaneously: the container runs in Host networking mode and Tailscale integration is enabled. In such a configuration, network traffic directed to the Unraid web interface does not go through standard user identity verification, resulting in root access being granted to every user within network range.

Impact

The attacker gains full, unauthorized access to the Unraid WebGUI administrative panel and web console with root privileges, allowing complete takeover of the server, data modification, malicious software installation, and access to all system resources.

Mitigation & patch

Update Unraid to version 7.0.1 or later, in which the vulnerability has been removed. Patch details are available in the official release notes at https://docs.unraid.net/unraid-os/release-notes/7.0.1/. Until the update is applied, it is recommended to disable the Use Tailscale option in the configuration of containers running in Host networking mode.

Who is affected

Unraid version 7.0.0 (before 7.0.1), when at least one container runs in Host networking mode with the Use Tailscale option enabled.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Container
CWE
References