Description
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authentication of such UniFi OS devices or instances.
Published: 2026-07-02
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Path Traversal flaw (CWE-22) that allows a malicious actor with network reach to supply a crafted file path to a UniFi OS device, causing the device to bypass its normal authentication checks. The result is unauthorized access to the device’s management interface and any functions exposed there, effectively granting administrative control.

Affected Systems

The flaw impacts Ubiquiti Inc. products, including Cloud Gateways, Cloud Keys, Dream Machines, Dream Routers, Dream Wall, Enterprise Firewall Core, Enterprise Fortress Gateway, Enterprise Video Recorders, Express 7, Network Attached Storage, Network Video Recorders, and UniFi OS Server. Specific affected firmware revisions are not listed in the advisory, so users should verify that their device version is either the patched release or has the path‑traversal fix applied.

Risk and Exploitability

This vulnerability carries a CVSS base score of 8.6, indicating high severity. The EPSS score is below 1 %, and it is not included in the CISA KEV catalog, implying it is infrequently targeted. Based on the description, it is inferred that the attack vector requires network access to the UniFi OS device’s management interface; an attacker must be able to reach the device’s API or web interface to exploit the path‑traversal and bypass authentication, gaining full administrative control without valid credentials.

Generated by OpenCVE AI on July 22, 2026 at 13:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest UniFi OS firmware that includes the path‑traversal fix referenced in Ubiquiti Security Advisory Bulletin 066.
  • If upgrading firmware is not immediately possible, isolate the affected device from unmanaged networks and restrict management‑interface access to trusted hosts only.
  • Configure the device to require authentication for all API and administrative routes; disable or restrict public access to the vulnerable endpoints.

Generated by OpenCVE AI on July 22, 2026 at 13:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Authentication Bypass in Ubiquiti UniFi OS

Fri, 17 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Authentication Bypass in Ubiquiti UniFi OS

Wed, 15 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access via Path Traversal in UniFi OS

Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access via Path Traversal in UniFi OS

Thu, 09 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Path Traversal in UniFi OS

Wed, 08 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Path Traversal in UniFi OS

Tue, 07 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in UniFi OS Enables Authentication Bypass

Tue, 07 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in UniFi OS Enables Authentication Bypass

Mon, 06 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in Ubiquiti UniFi OS Enabling Authentication Bypass

Sun, 05 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in Ubiquiti UniFi OS Enabling Authentication Bypass

Sun, 05 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Path Traversal for Authentication Bypass in Ubiquiti UniFi OS

Sun, 05 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Path Traversal for Authentication Bypass in Ubiquiti UniFi OS

Sat, 04 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Enables Authentication Bypass on Ubiquiti Unifi OS Devices

Fri, 03 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Path Traversal Enables Authentication Bypass on Ubiquiti Unifi OS Devices

Fri, 03 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title UniFi OS Path Traversal Authentication Bypass Vulnerability

Fri, 03 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title UniFi OS Path Traversal Authentication Bypass Vulnerability

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authentication of such UniFi OS devices or instances.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-02T16:09:42.714Z

Reserved: 2026-06-13T15:00:00.604Z

Link: CVE-2026-54403

cve-icon Vulnrichment

Updated: 2026-07-02T16:09:39.664Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T13:45:02Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')