SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2025-56798

HIGH · CVSS 8.8 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Unraid OS versions 6.12.14 and earlier are vulnerable to a Cross-Site Request Forgery (CSRF) attack that exploits a weak same-site policy for authentication cookies, potentially allowing remote attackers to escalate privileges. Organizations using affected versions of Unraid OS should prioritize addressing this vulnerability to prevent unauthorized access and potential compromise of their systems. Immediate action is recommended for those managing sensitive data or critical infrastructure within their Unraid environments.

CVE
CVE-2025-56798
Severity
HIGH
CVSS
8.8
EPSS
0.20%

Original NVD Description

Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows remote attackers to escalate privileges via the Unraid authentication cookie's lax same-site policy.