oM noM Security Feeds cve
vulnerability context

CVE-2026-9772

CVSS 8.8 HIGHEPSS 62%CWE-78OTX 6 pulses

Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid. Authentication is required to exploit this vulnerability. The specific flaw exists within FileUpload.php. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the www-data user. Was ZDI-CAN-30116.

Published 2026-06-24 · last modified 2026-06-26

details

CISA KEV status
Not in catalog
CVSS v3
8.8 / HIGH
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
62% percentile (score 0.0111)
CWE
CWE-78
OTX pulses
6 total, 0 recent

source mentions 2

source consensus

  • Bluesky:@cyberhub.blog
  • Bluesky
Want the 3-bullet summary of CVE-2026-9772, plus webhook alerts when KEV is updated? Pro is $10/mo.