LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-5849: Unraid Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-5849 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Unraid contains an authentication bypass vulnerability that allows attackers to gain access to the administrative interface. This CVE is chainable with CVE-2020-5847 for remote code execution.

CVE-2020-5849 is an authentication bypass in Unraid that can let an attacker reach the administrative interface without valid credentials. CISA notes it is chainable with CVE-2020-5847 to achieve remote code execution, so a successful bypass can escalate from unauthorized admin access to full system compromise on exposed hosts.

For IT and security teams running Unraid as a NAS or home-lab/server platform, this matters because the admin interface is a high-value target. Confirm exact affected builds, fixed releases, and deployment guidance against the vendor advisory before acting.

How it works

The weakness is classified under CWE-287 (Improper Authentication) and CWE-697 (Incorrect Comparison). In plain terms, the product fails to enforce authentication correctly for the administrative interface, so an attacker who can reach the service may bypass login checks and obtain admin-level access.

Once that access is gained, the same host may be further abused. CISA states this CVE is chainable with CVE-2020-5847 for remote code execution. Do not assume a specific request path, parameter, or payload; those details must be taken from the vendor advisory and any accompanying technical analysis. Treat any unauthenticated reachability to the Unraid admin UI as a serious exposure until patched and verified.

Am I affected? How to find it in your systems

Unraid is commonly deployed as a storage and virtualization appliance on dedicated hardware or in lab and small-business environments. Inventory every system that presents an Unraid management interface, including those reachable only on internal networks or via VPN.

How to remediate

Patch first. Apply the updates specified by the vendor for Unraid, following their instructions exactly. CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

Reduce exposure until the vendor update can be installed.

If your data may have been exposed

Actively exploited authentication-bypass and RCE chains can lead to full host compromise and data theft. If this system was reachable and unpatched during the vulnerable period, assume possible unauthorized admin access, rotate credentials and keys stored on or used by the host, review file shares and backups for tampering, and follow your incident-response process. Known ransomware use is not documented for this CVE in the provided facts; still treat any confirmed intrusion as a potential breach. You can run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in public dumps while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedUnraid · Unraid
WeaknessCWE-287
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities