CVE-2025-56798

Lime Technology, Inc. · Unraid OS

A Cross-Site Request Forgery vulnerability in Unraid OS allows unauthenticated remote attackers to perform unauthorized actions and escalate privileges due to lax cookie policies.

Executive summary

A high-severity Cross-Site Request Forgery vulnerability in Unraid OS allows remote attackers to escalate privileges, posing a significant risk to system integrity and administrative control.

Vulnerability

This is a Cross-Site Request Forgery (CSRF) vulnerability occurring in the authentication cookie management of the Unraid OS. It permits an unauthenticated remote attacker to trick a user into executing unintended actions, leading to privilege escalation.

Business impact

The ability for an unauthenticated attacker to escalate privileges via CSRF presents a severe threat to the confidentiality, integrity, and availability of the Unraid OS environment. With a CVSS score of 8.8, this vulnerability carries a high impact rating, as successful exploitation could lead to full administrative compromise, unauthorized data access, and potential system-wide disruption.

Remediation

Immediate Action: Monitor official communication from Lime Technology for the release of a security update and apply it immediately upon availability.

Proactive Monitoring: Review web server and authentication logs for suspicious patterns, specifically focusing on unexpected administrative actions or requests originating from external domains.

Compensating Controls: Implement a strict Web Application Firewall (WAF) policy to filter and block suspicious cross-site requests, and ensure that browser-based security policies for cookies are enforced where possible.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high CVSS score and the presence of a known proof-of-concept, this vulnerability must be treated as a priority. Administrators should restrict access to the Unraid management interface to trusted networks only and prepare to deploy the vendor-supplied patch as soon as it is released to prevent unauthorized privilege escalation.

Sources