← Vulnerability feed

Vulnerability record · CVE-2020-5847 · published 16 March 2020

CVE-2020-5847: Unraid unauthenticated remote code execution as root

Unraid · Unraid

Unraid through 6.8.0 contains a remote code execution flaw that is reachable without authentication, as reflected in the CVSS vector (AV:N/AC:L/PR:N/UI:N) and the referenced exploit title describing an authentication bypass leading to arbitrary code execution as root. The record gives no root-cause detail beyond an 'Other' CWE, so the exact vulnerable component is not specified. It matters because a network-reachable, pre-auth RCE on a storage/NAS host gives an attacker full control of the device and its data.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 EPSS 96% · top 0.1%
9.8CVSS 3.1 base score, v2 10.0
96%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
9References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Unraid through 6.8.0 allows Remote Code Execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: medium.

critical priorityPre-auth network RCE as root on an internet-exposed appliance, with KEV listing and near-maximum EPSS.

What it is

Unraid through 6.8.0 contains a remote code execution flaw that is reachable without authentication, as reflected in the CVSS vector (AV:N/AC:L/PR:N/UI:N) and the referenced exploit title describing an authentication bypass leading to arbitrary code execution as root. The record gives no root-cause detail beyond an 'Other' CWE, so the exact vulnerable component is not specified. It matters because a network-reachable, pre-auth RCE on a storage/NAS host gives an attacker full control of the device and its data.

Impact

An attacker gains arbitrary code execution with root privileges on the Unraid host, allowing full compromise of the system, its stored data and any attached services.

Attack surface

Reachable over the network with no authentication and no user interaction required, per the CVSS vector and the referenced authentication-bypass exploit. The specific exposed service or endpoint is not identified in the record.

Exploitation

Listed in CISA KEV since 2021-11-03 with a required action to apply vendor updates, and EPSS is very high (0.958, 99.9th percentile); public exploit references are tagged Exploit. No known ransomware campaign use is recorded.

What to do

  • Upgrade Unraid to a version later than 6.8.0 per vendor instructions; the record does not enumerate fixed versions.
  • Restrict network access to the Unraid web interface and management ports to trusted hosts only.
  • Place the Unraid host behind a firewall or VPN rather than exposing it directly to the internet.
  • Monitor vendor announcements for the applicable fixed release and confirm the upgrade completed.

Detection

  • Hunt for unexpected outbound connections or new processes spawned by the Unraid web service.
  • Review web server and application logs for requests matching the published authentication-bypass exploit pattern.
  • Alert on new or modified files in web-accessible directories and on unexpected root-level command execution.
  • Monitor for authentication anomalies or access to management endpoints from untrusted source addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-5847 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Unraid Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-5847 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2020-5847), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.