CVE-2025-29266: Unraid

Critical severity, CVSS 9.6. EPSS: 0.4% chance of exploitation in the next 30 days.

Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication if a container is running in Host networking mode with Use Tailscale enabled.

Affected products

  • Unraid Unraid: from 7.0.0, before 7.0.1 (fixed in 7.0.1)

Published 2025-03-31. Last modified 2026-06-17.