Impact
Cross‑Site Request Forgery in Unraid OS 6.12.14 and earlier allows attackers to hijack authentication cookies due to a lax SameSite policy. Threat actors can send forged requests from a victim's browser to the Unraid web interface, gaining the privileges associated with the authenticated session without needing to know the user’s credentials.
Affected Systems
Lime Technology’s Unraid OS version 6.12.14 and all earlier releases are impacted. The vulnerability resides in the web interface’s handling of authentication cookies, which is part of the operating system’s management UI.
Risk and Exploitability
Because the flaw expands the attack surface to any user with access to the web interface and can be triggered by a remote attacker using only a crafted URL or malicious webpage, the risk is high. No CVSS score is published, but the exploitation is straightforward and does not require local code execution. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the ability to elevate privileges without credentials makes this a critical issue for systems that expose the Unraid management console to the internet or to untrusted networks.
OpenCVE Enrichment