Description
A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi Network Application to escalate write permission on the host device.
Published: 2026-07-02
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A malicious actor with network access and high privileges can exploit a path traversal flaw (CWE‑22) in the self‑hosted UniFi Network Application to write arbitrary files on the host. By submitting a crafted file path, the attacker can create or overwrite files, thereby compromising the integrity of the operating system. The vulnerability grants the attacker write access on the host, which may enable further malicious activity, but the CVE description does not confirm arbitrary code execution.

Affected Systems

All self‑hosted installations of the UniFi Network Application from Ubiquiti Inc. are affected. No specific version range is provided by the vendor, so any deployment that has not yet applied a vendor fix may be vulnerable. Verify your installation against Ubiquiti’s release notes for remediation details.

Risk and Exploitability

The high CVSS score of 8.7 signals a serious vulnerability. The EPSS score of less than 1% indicates that exploitation has not yet been widely observed. Attackers need network connectivity to the UniFi controller and sufficient privileges to submit a crafted request to trigger the path traversal. Successful exploitation results in the attacker obtaining the ability to write arbitrary files to the host operating system, which can compromise system integrity and may facilitate later attacks. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on July 22, 2026 at 13:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security patch for the UniFi Network Application as specified in Ubiquiti’s advisory.
  • If no patch is available, upgrade to the latest supported version of the UniFi Network Application.
  • Restrict network access to the controller by placing it behind a firewall or internal VLAN and enforcing strict user‑role permissions to limit high‑privilege accounts.

Generated by OpenCVE AI on July 22, 2026 at 13:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Path Traversal in UniFi Network Application Allows Host Write Escalation

Fri, 17 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Path Traversal in UniFi Network Application Allows Host Write Escalation

Thu, 16 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Path Traversal in UniFi Network Application

Tue, 14 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Path Traversal in UniFi Network Application

Mon, 13 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Path Traversal in UniFi Network Application

Sun, 12 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Path Traversal in UniFi Network Application

Sat, 11 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Path Traversal in Ubiquiti UniFi Network Application Allows Host Write Access

Fri, 10 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Path Traversal in Ubiquiti UniFi Network Application Allows Host Write Access

Thu, 09 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Path Traversal in Self‑Hosted UniFi Network Application Enables Host Write Access

Wed, 08 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Path Traversal in Self‑Hosted UniFi Network Application Enables Host Write Access

Wed, 08 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Path Traversal in UniFi Network Application

Tue, 07 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Path Traversal in UniFi Network Application

Tue, 07 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Privilege Escalation in UniFi Network Application

Mon, 06 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Privilege Escalation in UniFi Network Application

Mon, 06 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Enabling Privilege Escalation on UniFi Network Application

Sun, 05 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Enabling Privilege Escalation on UniFi Network Application

Sun, 05 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Path Traversal in UniFi Network Application Enables Privilege Escalation

Sun, 05 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Path Traversal in UniFi Network Application Enables Privilege Escalation

Sat, 04 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Path Traversal in UniFi Network Application Enables Host Write Access for Privilege Escalation

Fri, 03 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Path Traversal in UniFi Network Application Enables Host Write Access for Privilege Escalation

Fri, 03 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Path Traversal in UniFi Network Application Enables Host Write Escalation

Thu, 02 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Path Traversal in UniFi Network Application Enables Host Write Escalation

Thu, 02 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Ubiquiti
Ubiquiti unifi Network Application
Vendors & Products Ubiquiti
Ubiquiti unifi Network Application

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi Network Application to escalate write permission on the host device.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H'}


Subscriptions

Ubiquiti Unifi Network Application
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-02T16:10:43.419Z

Reserved: 2026-06-13T15:00:00.605Z

Link: CVE-2026-54406

cve-icon Vulnrichment

Updated: 2026-07-02T16:10:40.652Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T13:45:02Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')