Description
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Protect Floodlight devices to access files on the UniFi Protect Floodlight.
Published: 2026-07-02
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A path traversal flaw in UniFi Protect Floodlight devices allows a network‑connected attacker to read arbitrary files stored on the device. Exploitation requires only that the attacker can reach the device’s web or management interface; by sending requests containing crafted directory traversal sequences, the attacker can bypass the intended file path boundaries and disclose sensitive configuration or system files. The vulnerability is a classic input validation error (CWE‑22) and does not provide code execution, privilege escalation, or denial of service.

Affected Systems

The vulnerability affects devices built by Ubiquiti Inc under the UniFi Protect Floodlight line. The advisory does not enumerate specific firmware or hardware revisions, so any device that incorporates the vulnerable component could be impacted.

Risk and Exploitability

The CVSS score of 7.5 indicates a high‑severity flaw that primarily threatens confidentiality. The EPSS score of < 1 % highlights a very low likelihood of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, a local‑network attacker who can reach the floodlight’s management or API endpoints can craft a request that traverses directories and reads files outside the intended root. Therefore, mitigation through firmware updates and network segmentation is critical to reduce risk, even though the probability of exploitation is currently low.

Generated by OpenCVE AI on July 21, 2026 at 11:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available Ubiquiti firmware or software update that addresses the path traversal flaw, following vendor release notes.
  • Limit access to the floodlight’s management interface by placing the device on a dedicated subnet and permitting only trusted IP addresses through firewall rules or by configuring VLAN segregation.
  • If a patch cannot be applied immediately, isolate the device from the rest of the network, enforce VPN‑only management access, and disable any unnecessary web or API services to reduce exposure.

Generated by OpenCVE AI on July 21, 2026 at 11:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Path Traversal Allowing Remote File Read in UniFi Protect Floodlight Devices

Wed, 15 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Allowing Remote File Read in UniFi Protect Floodlight Devices

Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Path Traversal in UniFi Protect Floodlight Allows Remote File Read

Mon, 13 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Path Traversal in UniFi Protect Floodlight Allows Remote File Read

Sun, 12 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in UniFi Protect Floodlight Devices

Sat, 11 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in UniFi Protect Floodlight Devices

Fri, 10 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title UniFi Protect Floodlight Path Traversal Enables Remote File Read

Thu, 09 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title UniFi Protect Floodlight Path Traversal Enables Remote File Read

Thu, 09 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Path Traversal in UniFi Protect Floodlight Allowing Remote File Read

Wed, 08 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Path Traversal in UniFi Protect Floodlight Allowing Remote File Read

Tue, 07 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability Enables Remote File Read on UniFi Protect Floodlight

Mon, 06 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability Enables Remote File Read on UniFi Protect Floodlight

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Ubiquiti
Ubiquiti unifi Protect Floodlight
Vendors & Products Ubiquiti
Ubiquiti unifi Protect Floodlight

Mon, 06 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in Ubiquiti UniFi Protect Floodlight Allows Remote File Read

Sun, 05 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in Ubiquiti UniFi Protect Floodlight Allows Remote File Read

Sun, 05 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Path Traversal Allows Remote File Read in Ubiquiti UniFi Protect Floodlight

Sun, 05 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Allows Remote File Read in Ubiquiti UniFi Protect Floodlight

Sat, 04 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title UniFi Protect Floodlight Path Traversal Enables Remote File Read

Sat, 04 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title UniFi Protect Floodlight Path Traversal Enables Remote File Read

Fri, 03 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Path Traversal in UniFi Protect Floodlight Enables File Read

Fri, 03 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Path Traversal in UniFi Protect Floodlight Enables File Read

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Protect Floodlight devices to access files on the UniFi Protect Floodlight.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ubiquiti Unifi Protect Floodlight
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-02T15:51:52.648Z

Reserved: 2026-06-16T15:00:01.614Z

Link: CVE-2026-55111

cve-icon Vulnrichment

Updated: 2026-07-02T15:49:27.527Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:15:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')