CVE-2026-9772Disclosure(unraid / unraid)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch unraid unraid systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid. Authentication is required to exploit this vulnerability. The specific flaw exists within FileUpload.php. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the www-data user. Was ZDI-CAN-30116.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • unraid

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-06-24); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
unraid

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-06-24: 1Mentions · 2026-06-25: 1Mentions · 2026-06-26: 1Patch / Workaround · 2026-06-26: 1Technical Details · 2026-06-24: 1Technical Details · 2026-06-26: 106-2406-2506-26
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-241
Disclosure1
2026-06-251
General1
2026-06-261
Patch1
Full discourse3 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-385|CVE-2026-9772] Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability (CVSS 8.8; Credit: Swagat Kumar Mishra(https://www.linkedin.com/in/swagatkumar/)) https://www.zerodayinitiative.com/advisories/ZDI-26-385/

    Post summary

    The advisory warns of a remote code execution flaw in Unraid’s file upload handling (CVE‑2026‑9772), providing vulnerability details and a link to the Zero Day Initiative report.

    010511.0K
    5.6K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH SEVERITY: CVE-2026-9772 (CVSS 8.8) Unraid Web Server FileUpload command injection RCE. Authenticated attackers can execute arbitrary code via improper input validation in FileUpload[.]php. Patch immediately! #CVE #Vulnerability #PatchNow https://t.co/HxUcq8McT2

    Post summary

    The tweet announces CVE‑2026‑9772, an authenticated RCE via command injection in FileUpload.php, urges immediate patching, but provides no PoC or exploit details.

    0000046
    52 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-9772 Remote Code Execution in Unraid Web Server FileUpload Comm... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-9772 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post merely references CVE‑2026‑9772 and links to a vulnerability detail page without providing any technical, PoC, or exploitation information.

    00000135
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSunraidunraid---

Explore more