Skip to content
COOEY

FAIL › dossier

Unraid

VENDOR

· dossier confidence 40%

Unraid is a private software vendor providing a Linux-based storage server operating system. The company has a documented history of high-severity remote code execution vulnerabilities in its administrative interface, indicating potential weaknesses in input validation and authentication mechanisms.

PROFILE
Categorysoftware vendorWhat they doUnraid is a Linux-based operating system for personal and enterprise storage servers, allowing users to create custom storage pools with mixed drive sizes and configurations.HQUnited States Websitehttps://unraid.net ↗
SECURITY POSTURE

The company has a documented history of high-severity remote code execution vulnerabilities in its administrative interface, indicating potential weaknesses in input validation and authentication mechanisms.

Notable failures
  • CVE-2020-5849 authentication bypass
  • CVE-2020-5847 insecure extract PHP function RCE
Patterns: unpatched edge-device RCEs; insecure PHP function usage
FAILURE HISTORY · 4
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2020-5847 high Unraid's insecure use of the extract PHP function allows remote code execution as root, enabling attackers to compromise storage servers.
2021-11-03 CVE-2020-5847 high Unraid's insecure use of the extract PHP function allows remote code execution as root, enabling attackers to compromise storage servers.
2021-11-03 CVE-2020-5849 high Unraid's authentication bypass vulnerability allowed attackers to access the administrative interface, which can be chained with another CVE for remote code execution.
2021-11-03 CVE-2020-5849 high Unraid's authentication bypass vulnerability allowed attackers to access the administrative interface, which can be chained with another CVE for remote code execution.
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Unraid's authentication bypass vulnerability was widely recognized as a critical flaw, especially given its inclusion in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploit
synthesissevere-fallout-0.60
Unraid's insecure use of PHP extract function allowed remote root code execution, a critical flaw with severe implications for users relying on its security.
cooey ↗severe-fallout-0.80
NVD entry confirms the vulnerability allows attackers to bypass authentication and gain access to the administrative interface, chainable with another CVE for remote code execution, indicating severe
"Unraid contains an authentication bypass vulnerability that allows attackers to gain access to the administrative interface. This CVE is chainable with CVE-2020-5847 for remote code execution."
CISA ↗severe-fallout-0.50
CISA's inclusion of the vulnerability in the KEV catalog signals active exploitation, reflecting severe fallout for Unraid and its users.
"CISA Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
www.cvefind.com ↗severe-fallout+0.00
CVEFind provides neutral, factual data about the vulnerability without commentary on Unraid's handling.
"CISA Known Exploited Vulnerabilities (KEV) is an initiative that identifies and publishes a list of known exploited vulnerabilities."
NIST ↗severe-fallout+0.00
NIST's NVD entry is neutral, providing a factual record of the vulnerability without sentiment.
NVD ↗severe-fallout+0.00
OpenCVE provides neutral, factual data about CVEs without commentary on Unraid's handling.
app.opencve.io ↗severe-fallout-0.50
CVEFeed's emphasis on KEV as a high-signal input for risk-based patch management underscores the severity of the vulnerability's exploitation.
"Because each KEV entry carries direct evidence of active exploitation, the catalog is one of the highest-signal inputs for risk-based patch mana"
cooey ↗severe-fallout-0.60
The NVD entry highlights a critical remote code execution vulnerability in Unraid, indicating a severe security failure.
"Unraid contains a vulnerability due to the insecure use of the extract PHP function that can be abused to execute remote code as root."
Open questions: Exact founding year · Specific headquarters location · Current employee count · Patch response time for CVE-2020-5849
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-17 03:51:59.646705+00:00