Search

Find a vulnerability

Search criteria

    24 vulnerabilities found for Express by Ubiquiti Inc

    CVE-2026-95862 (GCVE-0-2026-95862)

    Vulnerability from nvd – Published: 2026-09-22 18:49 – Updated: 2026-09-22 19:35
    VLAI
    Summary
    A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-22 19:34 UTC
    CWE
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-95862",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-22T19:34:47.330586Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-22T19:35:00.419Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Dream Machines",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Firewalls",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Routers",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Cloud Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Wall",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "4.0.21",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express 7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UniFi Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.26",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device."
                }
              ],
              "value": "A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787 Out-of-bounds write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-22T18:49:39.376Z",
            "orgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
            "shortName": "Ubiquiti"
          },
          "references": [
            {
              "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-069-069/07e367a7-edec-4d85-a058-f97e5ce9ac9c"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
        "assignerShortName": "Ubiquiti",
        "cveId": "CVE-2026-95862",
        "datePublished": "2026-09-22T18:49:39.376Z",
        "dateReserved": "2026-09-22T16:47:10.352Z",
        "dateUpdated": "2026-09-22T19:35:00.419Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-95861 (GCVE-0-2026-95861)

    Vulnerability from nvd – Published: 2026-09-22 18:47 – Updated: 2026-09-22 19:34
    VLAI
    Summary
    A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-22 19:34 UTC
    CWE
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-95861",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-22T19:34:07.360109Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-22T19:34:16.989Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Dream Machines",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Firewalls",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Routers",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Cloud Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Wall",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "4.0.21",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express 7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UniFi Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.26",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device."
                }
              ],
              "value": "A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-674",
                  "description": "CWE-674: Uncontrolled Recursion",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-22T18:47:13.695Z",
            "orgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
            "shortName": "Ubiquiti"
          },
          "references": [
            {
              "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-069-069/07e367a7-edec-4d85-a058-f97e5ce9ac9c"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
        "assignerShortName": "Ubiquiti",
        "cveId": "CVE-2026-95861",
        "datePublished": "2026-09-22T18:47:13.695Z",
        "dateReserved": "2026-09-22T16:47:06.490Z",
        "dateUpdated": "2026-09-22T19:34:16.989Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77558 (GCVE-0-2026-77558)

    Vulnerability from nvd – Published: 2026-09-22 18:43 – Updated: 2026-09-22 19:33
    VLAI
    Summary
    A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-22 19:33 UTC
    CWE
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77558",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-22T19:33:45.709368Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-22T19:33:53.966Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Dream Machines",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Firewalls",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Routers",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Cloud Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Wall",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "4.0.21",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express 7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UniFi Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.26",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device."
                }
              ],
              "value": "A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-22T18:43:14.612Z",
            "orgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
            "shortName": "Ubiquiti"
          },
          "references": [
            {
              "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-069-069/07e367a7-edec-4d85-a058-f97e5ce9ac9c"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
        "assignerShortName": "Ubiquiti",
        "cveId": "CVE-2026-77558",
        "datePublished": "2026-09-22T18:43:14.612Z",
        "dateReserved": "2026-08-20T20:32:48.221Z",
        "dateUpdated": "2026-09-22T19:33:53.966Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77556 (GCVE-0-2026-77556)

    Vulnerability from nvd – Published: 2026-09-22 18:41 – Updated: 2026-09-22 19:33
    VLAI
    Summary
    A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-22 19:33 UTC
    CWE
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77556",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-22T19:33:13.667722Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-22T19:33:21.537Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Dream Machines",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Firewalls",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Routers",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Cloud Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Wall",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "4.0.21",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express 7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UniFi Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.26",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device."
                }
              ],
              "value": "A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-22T18:41:15.201Z",
            "orgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
            "shortName": "Ubiquiti"
          },
          "references": [
            {
              "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-069-069/07e367a7-edec-4d85-a058-f97e5ce9ac9c"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
        "assignerShortName": "Ubiquiti",
        "cveId": "CVE-2026-77556",
        "datePublished": "2026-09-22T18:41:15.201Z",
        "dateReserved": "2026-08-20T20:32:43.655Z",
        "dateUpdated": "2026-09-22T19:33:21.537Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77555 (GCVE-0-2026-77555)

    Vulnerability from nvd – Published: 2026-09-22 18:38 – Updated: 2026-09-22 19:32
    VLAI
    Summary
    A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-22 19:32 UTC
    CWE
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77555",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-22T19:32:45.935116Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-22T19:32:56.582Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Dream Machines",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Firewalls",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Routers",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Cloud Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Wall",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "4.0.21",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express 7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UniFi Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.26",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device."
                }
              ],
              "value": "A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787 Out-of-bounds write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-22T18:38:20.615Z",
            "orgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
            "shortName": "Ubiquiti"
          },
          "references": [
            {
              "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-069-069/07e367a7-edec-4d85-a058-f97e5ce9ac9c"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
        "assignerShortName": "Ubiquiti",
        "cveId": "CVE-2026-77555",
        "datePublished": "2026-09-22T18:38:20.615Z",
        "dateReserved": "2026-08-20T20:32:43.655Z",
        "dateUpdated": "2026-09-22T19:32:56.582Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77544 (GCVE-0-2026-77544)

    Vulnerability from nvd – Published: 2026-09-22 18:34 – Updated: 2026-09-22 19:32
    VLAI
    Summary
    A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-22 19:32 UTC
    CWE
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77544",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-22T19:32:07.314862Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-22T19:32:21.278Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Dream Machines",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Firewalls",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Routers",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Cloud Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Wall",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "4.0.21",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express 7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UniFi Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.26",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device."
                }
              ],
              "value": "A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787 Out-of-bounds write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-22T18:34:39.993Z",
            "orgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
            "shortName": "Ubiquiti"
          },
          "references": [
            {
              "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-069-069/07e367a7-edec-4d85-a058-f97e5ce9ac9c"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
        "assignerShortName": "Ubiquiti",
        "cveId": "CVE-2026-77544",
        "datePublished": "2026-09-22T18:34:39.993Z",
        "dateReserved": "2026-08-20T20:32:37.793Z",
        "dateUpdated": "2026-09-22T19:32:21.278Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77550 (GCVE-0-2026-77550)

    Vulnerability from nvd – Published: 2026-08-26 10:33 – Updated: 2026-08-27 03:56
    VLAI
    Summary
    A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-26 00:00 UTC
    CWE
    • CWE-93 - Improper neutralization of CRLF sequences ('CRLF injection')
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77550",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-26T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-27T03:56:41.054Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "UniFi OS Server",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Cloud Keys",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Network Video Recorders",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Network Video Recorders",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Network Attached Storage",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Machines",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Firewall Core",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Routers",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Fortress Gateway",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Cloud Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Wall",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express 7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Network Attached Storage",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.32",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "4.0.17",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances."
                }
              ],
              "value": "A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 10,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-93",
                  "description": "CWE-93 Improper neutralization of CRLF sequences (\u0027CRLF injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-26T10:33:29.989Z",
            "orgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
            "shortName": "Ubiquiti"
          },
          "references": [
            {
              "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
        "assignerShortName": "Ubiquiti",
        "cveId": "CVE-2026-77550",
        "datePublished": "2026-08-26T10:33:29.989Z",
        "dateReserved": "2026-08-20T20:32:37.794Z",
        "dateUpdated": "2026-08-27T03:56:41.054Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77549 (GCVE-0-2026-77549)

    Vulnerability from nvd – Published: 2026-08-26 10:30 – Updated: 2026-08-27 03:56
    VLAI
    Summary
    A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-26 00:00 UTC
    CWE
    • CWE-93 - Improper neutralization of CRLF sequences ('CRLF injection')
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77549",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-26T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-27T03:56:37.824Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "UniFi OS Server",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Cloud Keys",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Network Video Recorders",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Network Video Recorders",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Network Attached Storage",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Machines",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Firewall Core",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Routers",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Fortress Gateway",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Cloud Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Wall",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express 7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Network Attached Storage",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.32",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "4.0.17",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances."
                }
              ],
              "value": "A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-93",
                  "description": "CWE-93 Improper neutralization of CRLF sequences (\u0027CRLF injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-26T10:30:06.712Z",
            "orgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
            "shortName": "Ubiquiti"
          },
          "references": [
            {
              "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
        "assignerShortName": "Ubiquiti",
        "cveId": "CVE-2026-77549",
        "datePublished": "2026-08-26T10:30:06.712Z",
        "dateReserved": "2026-08-20T20:32:37.794Z",
        "dateUpdated": "2026-08-27T03:56:37.824Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-47370 (GCVE-0-2026-47370)

    Vulnerability from nvd – Published: 2026-06-12 02:27 – Updated: 2026-06-13 03:55
    VLAI
    Summary
    A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Command Injection within such UniFi OS devices or instances.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-12 00:00 UTC
    CWE
    • CWE-20 - Improper Input Validation
    Impacted products
    Vendor Product Version
    Ubiquiti Inc UniFi OS Server Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc Express Affected: 0 , < 4.0.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-Pro Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-SE Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-Pro-Max Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-Beast Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc EFG Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDW Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDR Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDR7 Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDR-5G Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc Express 7 Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-Pro Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-Instant Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-G2 Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-G2-Pro Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc ENVR Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc ENVR-Core Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-2 Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-4 Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-Pro Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-Pro-4 Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-Pro-8 Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCKP Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCK Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCK-Enterprise Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Ultra Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Max Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Fiber Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Industrial Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-47370",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-12T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-13T03:55:51.078Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "UniFi OS Server",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "4.0.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-SE",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-Pro-Max",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-Beast",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EFG",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDW",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDR",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDR7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDR-5G",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express 7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-Instant",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-G2",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-G2-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ENVR",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ENVR-Core",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-2",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-4",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-Pro-4",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-Pro-8",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCKP",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCK",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCK-Enterprise",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Ultra",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Max",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Fiber",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Industrial",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Command Injection within such UniFi OS devices or instances."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-12T02:27:43.642Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-065-065/aa46a22b-fc43-4eae-9382-6fc8feda967a"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-47370",
        "datePublished": "2026-06-12T02:27:43.642Z",
        "dateReserved": "2026-05-19T15:00:09.320Z",
        "dateUpdated": "2026-06-13T03:55:51.078Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-47369 (GCVE-0-2026-47369)

    Vulnerability from nvd – Published: 2026-06-12 02:27 – Updated: 2026-06-13 03:55
    VLAI
    Summary
    A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-12 00:00 UTC
    CWE
    • CWE-20 - Improper Input Validation
    Impacted products
    Vendor Product Version
    Ubiquiti Inc UniFi OS Server Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc Express Affected: 0 , < 4.0.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-Pro Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-SE Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-Pro-Max Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-Beast Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc EFG Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDW Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDR Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDR7 Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDR-5G Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc Express 7 Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-Pro Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-Instant Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-G2 Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-G2-Pro Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc ENVR Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc ENVR-Core Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-2 Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-4 Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-Pro Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-Pro-4 Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-Pro-8 Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCKP Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCK Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCK-Enterprise Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Ultra Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Max Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Fiber Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Industrial Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-47369",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-12T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-13T03:55:49.944Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "UniFi OS Server",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "4.0.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-SE",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-Pro-Max",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-Beast",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EFG",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDW",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDR",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDR7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDR-5G",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express 7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-Instant",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-G2",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-G2-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ENVR",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ENVR-Core",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-2",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-4",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-Pro-4",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-Pro-8",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCKP",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCK",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCK-Enterprise",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Ultra",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Max",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Fiber",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Industrial",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-12T02:27:43.612Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-065-065/aa46a22b-fc43-4eae-9382-6fc8feda967a"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-47369",
        "datePublished": "2026-06-12T02:27:43.612Z",
        "dateReserved": "2026-05-19T15:00:09.320Z",
        "dateUpdated": "2026-06-13T03:55:49.944Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-47368 (GCVE-0-2026-47368)

    Vulnerability from nvd – Published: 2026-06-12 02:27 – Updated: 2026-06-12 14:30
    VLAI
    Summary
    A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data from such UniFi OS devices or instances.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-12 14:29 UTC
    CWE
    Impacted products
    Vendor Product Version
    Ubiquiti Inc UniFi OS Server Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc Express Affected: 0 , < 4.0.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-Pro Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-SE Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-Pro-Max Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-Beast Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc EFG Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDW Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDR Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDR7 Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDR-5G Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc Express 7 Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-Pro Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-Instant Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-G2 Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-G2-Pro Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc ENVR Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc ENVR-Core Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-2 Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-4 Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-Pro Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-Pro-4 Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-Pro-8 Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCKP Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCK Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCK-Enterprise Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Ultra Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Max Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Fiber Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Industrial Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-47368",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-12T14:29:49.966121Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-12T14:30:10.779Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "UniFi OS Server",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "4.0.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-SE",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-Pro-Max",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-Beast",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EFG",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDW",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDR",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDR7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDR-5G",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express 7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-Instant",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-G2",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-G2-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ENVR",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ENVR-Core",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-2",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-4",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-Pro-4",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-Pro-8",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCKP",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCK",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCK-Enterprise",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Ultra",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Max",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Fiber",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Industrial",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data from such UniFi OS devices or instances."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Path Traversal",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-12T02:27:43.525Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-065-065/aa46a22b-fc43-4eae-9382-6fc8feda967a"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-47368",
        "datePublished": "2026-06-12T02:27:43.525Z",
        "dateReserved": "2026-05-19T15:00:09.320Z",
        "dateUpdated": "2026-06-12T14:30:10.779Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-34909 (GCVE-0-2026-34909)

    Vulnerability from nvd – Published: 2026-05-22 00:43 – Updated: 2026-06-24 03:56
    VLAI CISA Previdian
    Summary
    A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-23 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    Ubiquiti Inc UniFi OS Server Affected: 0 , < 5.0.8 (semver)
    Create a notification for this product.
    Ubiquiti Inc Express Affected: 0 , < 4.0.14 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-Pro Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-SE Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-Pro-Max Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-Beast Affected: 0 , < 5.1.11 (semver)
    Create a notification for this product.
    Ubiquiti Inc EFG Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDW Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDR Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDR7 Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDR-5G Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc Express 7 Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-Pro Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-Instant Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-G2 Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-G2-Pro Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc ENVR Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc ENVR-Core Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-2 Affected: 0 , < 5.1.10 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-4 Affected: 0 , < 5.1.10 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-Pro Affected: 0 , < 5.1.10 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-Pro-4 Affected: 0 , < 5.1.10 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-Pro-8 Affected: 0 , < 5.1.10 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCKP Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCK Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCK-Enterprise Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Ultra Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Max Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Fiber Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Industrial Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-34909",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-23T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2026-06-23",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34909"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-24T03:56:19.760Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "third-party-advisory"
                ],
                "url": "https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/"
              },
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34909"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2026-06-23T00:00:00.000Z",
                "value": "CVE-2026-34909 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "UniFi OS Server",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.0.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "4.0.14",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-SE",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-Pro-Max",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-Beast",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.11",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EFG",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDW",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDR",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDR7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDR-5G",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express 7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-Instant",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-G2",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-G2-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ENVR",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ENVR-Core",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-2",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-4",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-Pro-4",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-Pro-8",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCKP",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCK",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCK-Enterprise",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Ultra",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Max",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Fiber",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Industrial",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 10,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Path Traversal",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-22T20:19:51.649Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-34909",
        "datePublished": "2026-05-22T00:43:49.072Z",
        "dateReserved": "2026-03-31T15:00:06.521Z",
        "dateUpdated": "2026-06-24T03:56:19.760Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-95862 (GCVE-0-2026-95862)

    Vulnerability from cvelistv5 – Published: 2026-09-22 18:49 – Updated: 2026-09-22 19:35
    VLAI
    Summary
    A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-22 19:34 UTC
    CWE
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-95862",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-22T19:34:47.330586Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-22T19:35:00.419Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Dream Machines",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Firewalls",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Routers",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Cloud Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Wall",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "4.0.21",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express 7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UniFi Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.26",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device."
                }
              ],
              "value": "A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787 Out-of-bounds write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-22T18:49:39.376Z",
            "orgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
            "shortName": "Ubiquiti"
          },
          "references": [
            {
              "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-069-069/07e367a7-edec-4d85-a058-f97e5ce9ac9c"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
        "assignerShortName": "Ubiquiti",
        "cveId": "CVE-2026-95862",
        "datePublished": "2026-09-22T18:49:39.376Z",
        "dateReserved": "2026-09-22T16:47:10.352Z",
        "dateUpdated": "2026-09-22T19:35:00.419Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-95861 (GCVE-0-2026-95861)

    Vulnerability from cvelistv5 – Published: 2026-09-22 18:47 – Updated: 2026-09-22 19:34
    VLAI
    Summary
    A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-22 19:34 UTC
    CWE
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-95861",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-22T19:34:07.360109Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-22T19:34:16.989Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Dream Machines",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Firewalls",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Routers",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Cloud Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Wall",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "4.0.21",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express 7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UniFi Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.26",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device."
                }
              ],
              "value": "A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-674",
                  "description": "CWE-674: Uncontrolled Recursion",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-22T18:47:13.695Z",
            "orgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
            "shortName": "Ubiquiti"
          },
          "references": [
            {
              "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-069-069/07e367a7-edec-4d85-a058-f97e5ce9ac9c"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
        "assignerShortName": "Ubiquiti",
        "cveId": "CVE-2026-95861",
        "datePublished": "2026-09-22T18:47:13.695Z",
        "dateReserved": "2026-09-22T16:47:06.490Z",
        "dateUpdated": "2026-09-22T19:34:16.989Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77558 (GCVE-0-2026-77558)

    Vulnerability from cvelistv5 – Published: 2026-09-22 18:43 – Updated: 2026-09-22 19:33
    VLAI
    Summary
    A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-22 19:33 UTC
    CWE
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77558",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-22T19:33:45.709368Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-22T19:33:53.966Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Dream Machines",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Firewalls",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Routers",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Cloud Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Wall",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "4.0.21",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express 7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UniFi Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.26",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device."
                }
              ],
              "value": "A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-22T18:43:14.612Z",
            "orgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
            "shortName": "Ubiquiti"
          },
          "references": [
            {
              "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-069-069/07e367a7-edec-4d85-a058-f97e5ce9ac9c"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
        "assignerShortName": "Ubiquiti",
        "cveId": "CVE-2026-77558",
        "datePublished": "2026-09-22T18:43:14.612Z",
        "dateReserved": "2026-08-20T20:32:48.221Z",
        "dateUpdated": "2026-09-22T19:33:53.966Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77556 (GCVE-0-2026-77556)

    Vulnerability from cvelistv5 – Published: 2026-09-22 18:41 – Updated: 2026-09-22 19:33
    VLAI
    Summary
    A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-22 19:33 UTC
    CWE
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77556",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-22T19:33:13.667722Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-22T19:33:21.537Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Dream Machines",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Firewalls",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Routers",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Cloud Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Wall",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "4.0.21",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express 7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UniFi Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.26",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device."
                }
              ],
              "value": "A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-22T18:41:15.201Z",
            "orgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
            "shortName": "Ubiquiti"
          },
          "references": [
            {
              "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-069-069/07e367a7-edec-4d85-a058-f97e5ce9ac9c"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
        "assignerShortName": "Ubiquiti",
        "cveId": "CVE-2026-77556",
        "datePublished": "2026-09-22T18:41:15.201Z",
        "dateReserved": "2026-08-20T20:32:43.655Z",
        "dateUpdated": "2026-09-22T19:33:21.537Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77555 (GCVE-0-2026-77555)

    Vulnerability from cvelistv5 – Published: 2026-09-22 18:38 – Updated: 2026-09-22 19:32
    VLAI
    Summary
    A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-22 19:32 UTC
    CWE
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77555",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-22T19:32:45.935116Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-22T19:32:56.582Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Dream Machines",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Firewalls",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Routers",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Cloud Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Wall",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "4.0.21",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express 7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UniFi Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.26",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device."
                }
              ],
              "value": "A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787 Out-of-bounds write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-22T18:38:20.615Z",
            "orgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
            "shortName": "Ubiquiti"
          },
          "references": [
            {
              "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-069-069/07e367a7-edec-4d85-a058-f97e5ce9ac9c"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
        "assignerShortName": "Ubiquiti",
        "cveId": "CVE-2026-77555",
        "datePublished": "2026-09-22T18:38:20.615Z",
        "dateReserved": "2026-08-20T20:32:43.655Z",
        "dateUpdated": "2026-09-22T19:32:56.582Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77544 (GCVE-0-2026-77544)

    Vulnerability from cvelistv5 – Published: 2026-09-22 18:34 – Updated: 2026-09-22 19:32
    VLAI
    Summary
    A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-22 19:32 UTC
    CWE
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77544",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-22T19:32:07.314862Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-22T19:32:21.278Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Dream Machines",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Firewalls",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Routers",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Cloud Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Wall",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "4.0.21",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express 7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UniFi Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.26",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device."
                }
              ],
              "value": "A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787 Out-of-bounds write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-22T18:34:39.993Z",
            "orgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
            "shortName": "Ubiquiti"
          },
          "references": [
            {
              "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-069-069/07e367a7-edec-4d85-a058-f97e5ce9ac9c"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
        "assignerShortName": "Ubiquiti",
        "cveId": "CVE-2026-77544",
        "datePublished": "2026-09-22T18:34:39.993Z",
        "dateReserved": "2026-08-20T20:32:37.793Z",
        "dateUpdated": "2026-09-22T19:32:21.278Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77550 (GCVE-0-2026-77550)

    Vulnerability from cvelistv5 – Published: 2026-08-26 10:33 – Updated: 2026-08-27 03:56
    VLAI
    Summary
    A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-26 00:00 UTC
    CWE
    • CWE-93 - Improper neutralization of CRLF sequences ('CRLF injection')
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77550",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-26T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-27T03:56:41.054Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "UniFi OS Server",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Cloud Keys",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Network Video Recorders",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Network Video Recorders",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Network Attached Storage",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Machines",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Firewall Core",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Routers",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Fortress Gateway",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Cloud Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Wall",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express 7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Network Attached Storage",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.32",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "4.0.17",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances."
                }
              ],
              "value": "A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 10,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-93",
                  "description": "CWE-93 Improper neutralization of CRLF sequences (\u0027CRLF injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-26T10:33:29.989Z",
            "orgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
            "shortName": "Ubiquiti"
          },
          "references": [
            {
              "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
        "assignerShortName": "Ubiquiti",
        "cveId": "CVE-2026-77550",
        "datePublished": "2026-08-26T10:33:29.989Z",
        "dateReserved": "2026-08-20T20:32:37.794Z",
        "dateUpdated": "2026-08-27T03:56:41.054Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77549 (GCVE-0-2026-77549)

    Vulnerability from cvelistv5 – Published: 2026-08-26 10:30 – Updated: 2026-08-27 03:56
    VLAI
    Summary
    A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-26 00:00 UTC
    CWE
    • CWE-93 - Improper neutralization of CRLF sequences ('CRLF injection')
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77549",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-26T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-27T03:56:37.824Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "UniFi OS Server",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Cloud Keys",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Network Video Recorders",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Network Video Recorders",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Network Attached Storage",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Machines",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Firewall Core",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Routers",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Enterprise Fortress Gateway",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Cloud Gateways",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Dream Wall",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express 7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.31",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Network Attached Storage",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.32",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "4.0.17",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances."
                }
              ],
              "value": "A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-93",
                  "description": "CWE-93 Improper neutralization of CRLF sequences (\u0027CRLF injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-26T10:30:06.712Z",
            "orgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
            "shortName": "Ubiquiti"
          },
          "references": [
            {
              "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "fe490ce8-0395-4072-90d8-2707e1bdf984",
        "assignerShortName": "Ubiquiti",
        "cveId": "CVE-2026-77549",
        "datePublished": "2026-08-26T10:30:06.712Z",
        "dateReserved": "2026-08-20T20:32:37.794Z",
        "dateUpdated": "2026-08-27T03:56:37.824Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-47370 (GCVE-0-2026-47370)

    Vulnerability from cvelistv5 – Published: 2026-06-12 02:27 – Updated: 2026-06-13 03:55
    VLAI
    Summary
    A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Command Injection within such UniFi OS devices or instances.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-12 00:00 UTC
    CWE
    • CWE-20 - Improper Input Validation
    Impacted products
    Vendor Product Version
    Ubiquiti Inc UniFi OS Server Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc Express Affected: 0 , < 4.0.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-Pro Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-SE Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-Pro-Max Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-Beast Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc EFG Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDW Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDR Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDR7 Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDR-5G Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc Express 7 Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-Pro Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-Instant Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-G2 Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-G2-Pro Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc ENVR Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc ENVR-Core Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-2 Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-4 Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-Pro Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-Pro-4 Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-Pro-8 Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCKP Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCK Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCK-Enterprise Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Ultra Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Max Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Fiber Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Industrial Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-47370",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-12T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-13T03:55:51.078Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "UniFi OS Server",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "4.0.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-SE",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-Pro-Max",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-Beast",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EFG",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDW",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDR",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDR7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDR-5G",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express 7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-Instant",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-G2",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-G2-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ENVR",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ENVR-Core",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-2",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-4",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-Pro-4",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-Pro-8",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCKP",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCK",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCK-Enterprise",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Ultra",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Max",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Fiber",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Industrial",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Command Injection within such UniFi OS devices or instances."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-12T02:27:43.642Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-065-065/aa46a22b-fc43-4eae-9382-6fc8feda967a"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-47370",
        "datePublished": "2026-06-12T02:27:43.642Z",
        "dateReserved": "2026-05-19T15:00:09.320Z",
        "dateUpdated": "2026-06-13T03:55:51.078Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-47369 (GCVE-0-2026-47369)

    Vulnerability from cvelistv5 – Published: 2026-06-12 02:27 – Updated: 2026-06-13 03:55
    VLAI
    Summary
    A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-12 00:00 UTC
    CWE
    • CWE-20 - Improper Input Validation
    Impacted products
    Vendor Product Version
    Ubiquiti Inc UniFi OS Server Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc Express Affected: 0 , < 4.0.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-Pro Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-SE Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-Pro-Max Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-Beast Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc EFG Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDW Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDR Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDR7 Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDR-5G Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc Express 7 Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-Pro Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-Instant Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-G2 Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-G2-Pro Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc ENVR Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc ENVR-Core Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-2 Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-4 Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-Pro Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-Pro-4 Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-Pro-8 Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCKP Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCK Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCK-Enterprise Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Ultra Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Max Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Fiber Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Industrial Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-47369",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-12T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-13T03:55:49.944Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "UniFi OS Server",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "4.0.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-SE",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-Pro-Max",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-Beast",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EFG",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDW",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDR",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDR7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDR-5G",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express 7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-Instant",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-G2",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-G2-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ENVR",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ENVR-Core",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-2",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-4",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-Pro-4",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-Pro-8",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCKP",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCK",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCK-Enterprise",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Ultra",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Max",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Fiber",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Industrial",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-12T02:27:43.612Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-065-065/aa46a22b-fc43-4eae-9382-6fc8feda967a"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-47369",
        "datePublished": "2026-06-12T02:27:43.612Z",
        "dateReserved": "2026-05-19T15:00:09.320Z",
        "dateUpdated": "2026-06-13T03:55:49.944Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-47368 (GCVE-0-2026-47368)

    Vulnerability from cvelistv5 – Published: 2026-06-12 02:27 – Updated: 2026-06-12 14:30
    VLAI
    Summary
    A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data from such UniFi OS devices or instances.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-12 14:29 UTC
    CWE
    Impacted products
    Vendor Product Version
    Ubiquiti Inc UniFi OS Server Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc Express Affected: 0 , < 4.0.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-Pro Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-SE Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-Pro-Max Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-Beast Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc EFG Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDW Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDR Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDR7 Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDR-5G Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc Express 7 Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-Pro Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-Instant Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-G2 Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-G2-Pro Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc ENVR Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc ENVR-Core Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-2 Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-4 Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-Pro Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-Pro-4 Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-Pro-8 Affected: 0 , < 5.1.16 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCKP Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCK Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCK-Enterprise Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Ultra Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Max Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Fiber Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Industrial Affected: 0 , < 5.1.15 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-47368",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-12T14:29:49.966121Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-12T14:30:10.779Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "UniFi OS Server",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "4.0.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-SE",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-Pro-Max",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-Beast",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EFG",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDW",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDR",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDR7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDR-5G",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express 7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-Instant",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-G2",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-G2-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ENVR",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ENVR-Core",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-2",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-4",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-Pro-4",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-Pro-8",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCKP",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCK",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCK-Enterprise",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Ultra",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Max",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Fiber",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Industrial",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data from such UniFi OS devices or instances."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Path Traversal",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-12T02:27:43.525Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-065-065/aa46a22b-fc43-4eae-9382-6fc8feda967a"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-47368",
        "datePublished": "2026-06-12T02:27:43.525Z",
        "dateReserved": "2026-05-19T15:00:09.320Z",
        "dateUpdated": "2026-06-12T14:30:10.779Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-34909 (GCVE-0-2026-34909)

    Vulnerability from cvelistv5 – Published: 2026-05-22 00:43 – Updated: 2026-06-24 03:56
    VLAI CISA Previdian
    Summary
    A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-23 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    Ubiquiti Inc UniFi OS Server Affected: 0 , < 5.0.8 (semver)
    Create a notification for this product.
    Ubiquiti Inc Express Affected: 0 , < 4.0.14 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-Pro Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-SE Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-Pro-Max Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDM-Beast Affected: 0 , < 5.1.11 (semver)
    Create a notification for this product.
    Ubiquiti Inc EFG Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDW Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDR Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDR7 Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UDR-5G Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc Express 7 Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-Pro Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-Instant Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-G2 Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNVR-G2-Pro Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc ENVR Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc ENVR-Core Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-2 Affected: 0 , < 5.1.10 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-4 Affected: 0 , < 5.1.10 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-Pro Affected: 0 , < 5.1.10 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-Pro-4 Affected: 0 , < 5.1.10 (semver)
    Create a notification for this product.
    Ubiquiti Inc UNAS-Pro-8 Affected: 0 , < 5.1.10 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCKP Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCK Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCK-Enterprise Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Ultra Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Max Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Fiber Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Ubiquiti Inc UCG-Industrial Affected: 0 , < 5.1.12 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-34909",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-23T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2026-06-23",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34909"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-24T03:56:19.760Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "third-party-advisory"
                ],
                "url": "https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/"
              },
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34909"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2026-06-23T00:00:00.000Z",
                "value": "CVE-2026-34909 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "UniFi OS Server",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.0.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "4.0.14",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-SE",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-Pro-Max",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDM-Beast",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.11",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EFG",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDW",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDR",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDR7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UDR-5G",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Express 7",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-Instant",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-G2",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNVR-G2-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ENVR",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ENVR-Core",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-2",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-4",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-Pro",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-Pro-4",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UNAS-Pro-8",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCKP",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCK",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCK-Enterprise",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Ultra",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Max",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Fiber",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UCG-Industrial",
              "vendor": "Ubiquiti Inc",
              "versions": [
                {
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 10,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Path Traversal",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-22T20:19:51.649Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-34909",
        "datePublished": "2026-05-22T00:43:49.072Z",
        "dateReserved": "2026-03-31T15:00:06.521Z",
        "dateUpdated": "2026-06-24T03:56:19.760Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }