Description
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authentication of such UniFi OS devices or instances.
Published: 2026-07-02
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a path traversal flaw (CWE‑22) that allows an attacker who can reach the UniFi OS device over the network to supply a malicious file path to the system. By exploiting this flaw, the attacker can bypass the device’s normal authentication checks, thereby gaining unauthorized access to the management interface. The description does not explicitly state which privileged actions become available, but based on the description it is inferred that bypassing authentication could enable the use of privileged functions.

Affected Systems

The flaw affects Ubiquiti Inc. devices running UniFi OS, including Cloud Gateways, Cloud Keys, Dream Machines, Dream Routers, Dream Wall, Enterprise Firewall Core, Enterprise Fortress Gateway, Enterprise Video Recorders, Express 7, Network Attached Storage, Network Video Recorders, and UniFi OS Server. Specific firmware revisions that contain the issue are not disclosed in the advisory; users should verify that their device version is either the patched release or has the path‑traversal fix applied.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity. The EPSS score of less than 1 % suggests the vulnerability is infrequently targeted. It is not listed in CISA KEV catalog. The vulnerability requires only network access to the UniFi OS device’s management interface; an attacker must be able to reach the device’s API or web interface to supply a path‑traversal request and bypass authentication.

Generated by OpenCVE AI on August 4, 2026 at 07:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest UniFi OS firmware that includes the path‑traversal fix referenced in Ubiquiti Security Advisory Bulletin 066.
  • Restrict the device’s management interface to trusted hosts or a subnet, and disable or limit access to vulnerable endpoints.
  • Enable authentication for all API and administrative routes, and consider using VLAN segmentation or a firewall to limit exposure.
  • Monitor logs for anomalous file path requests or authentication bypass attempts.

Generated by OpenCVE AI on August 4, 2026 at 07:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Path Traversal on Ubiquiti UniFi OS Devices

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability Allowing Authentication Bypass on UniFi OS Devices

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability Allowing Authentication Bypass on UniFi OS Devices

Wed, 22 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Authentication Bypass in Ubiquiti UniFi OS

Fri, 17 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Authentication Bypass in Ubiquiti UniFi OS

Wed, 15 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access via Path Traversal in UniFi OS

Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access via Path Traversal in UniFi OS

Thu, 09 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Path Traversal in UniFi OS

Wed, 08 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Path Traversal in UniFi OS

Tue, 07 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in UniFi OS Enables Authentication Bypass

Tue, 07 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in UniFi OS Enables Authentication Bypass

Mon, 06 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in Ubiquiti UniFi OS Enabling Authentication Bypass

Sun, 05 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in Ubiquiti UniFi OS Enabling Authentication Bypass

Sun, 05 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Path Traversal for Authentication Bypass in Ubiquiti UniFi OS

Sun, 05 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Path Traversal for Authentication Bypass in Ubiquiti UniFi OS

Sat, 04 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Enables Authentication Bypass on Ubiquiti Unifi OS Devices

Fri, 03 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Path Traversal Enables Authentication Bypass on Ubiquiti Unifi OS Devices

Fri, 03 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title UniFi OS Path Traversal Authentication Bypass Vulnerability

Fri, 03 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title UniFi OS Path Traversal Authentication Bypass Vulnerability

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authentication of such UniFi OS devices or instances.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Ui Enterprise Firewall Core Enterprise Firewall Core Firmware Enterprise Fortress Gateway Enterprise Fortress Gateway Firmware Enterprise Network Video Recorder Enterprise Network Video Recorder Core Enterprise Network Video Recorder Core Firmware Enterprise Network Video Recorder Firmware Unas 2 Unas 2 Firmware Unas 4 Unas 4 Firmware Unas Pro Unas Pro 4 Unas Pro 4 Firmware Unas Pro 8 Unas Pro 8 Firmware Unas Pro Firmware Unifi Cloud Gateway Fiber Unifi Cloud Gateway Fiber Firmware Unifi Cloud Gateway Industrial Unifi Cloud Gateway Industrial Firmware Unifi Cloud Gateway Max Unifi Cloud Gateway Max Firmware Unifi Cloud Gateway Ultra Unifi Cloud Gateway Ultra Firmware Unifi Cloud Key Plus Unifi Cloud Key Plus Firmware Unifi Cloudkey Unifi Cloudkey Enterprise Unifi Cloudkey Enterprise Firmware Unifi Cloudkey Firmware Unifi Dream Machine Unifi Dream Machine Beast Unifi Dream Machine Beast Firmware Unifi Dream Machine Firmware Unifi Dream Machine Pro Unifi Dream Machine Pro Firmware Unifi Dream Machine Pro Max Unifi Dream Machine Pro Max Firmware Unifi Dream Machine Special Edition Unifi Dream Machine Special Edition Firmware Unifi Dream Router Unifi Dream Router 5g Max Unifi Dream Router 5g Max Firmware Unifi Dream Router 7 Unifi Dream Router 7 Firmware Unifi Dream Router Firmware Unifi Dream Wall Unifi Dream Wall Firmware Unifi Express 7 Unifi Express 7 Firmware Unifi Network Video Recorder Unifi Network Video Recorder Firmware Unifi Network Video Recorder G2 Unifi Network Video Recorder G2 Firmware Unifi Network Video Recorder G2 Pro Unifi Network Video Recorder G2 Pro Firmware Unifi Network Video Recorder Instant Unifi Network Video Recorder Instant Firmware Unifi Network Video Recorder Pro Unifi Network Video Recorder Pro Firmware Unifi Os Server
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-02T16:09:42.714Z

Reserved: 2026-06-13T15:00:00.604Z

Link: CVE-2026-54403

cve-icon Vulnrichment

Updated: 2026-07-02T16:09:39.664Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-02T15:17:03.947

Modified: 2026-07-10T02:46:57.573

Link: CVE-2026-54403

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T08:00:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')