CVE-2026-54402
unifi_os_server: Improper Input Validation (CVE-2026-54402)
Affected
- ui/unifi_network_video_recorder_g2_pro_firmware
between *..5.1.15 - ui/unifi_cloud_gateway_ultra_firmware
between *..5.1.15 - ui/unifi_cloud_gateway_max_firmware
between *..5.1.15 - ui/unifi_cloud_gateway_industrial_firmware
between *..5.1.15 - ui/unifi_cloud_gateway_fiber_firmware
between *..5.1.15 - ui/unas_2_firmware
between *..5.1.16 - ui/unas_4_firmware
between *..5.1.16 - ui/unas_pro_firmware
between *..5.1.16 - ui/unas_pro_4_firmware
between *..5.1.16 - ui/unas_pro_8_firmware
between *..5.1.16 - ui/enterprise_firewall_core_firmware
between *..5.1.18 - ui/unifi_dream_router_5g_max_firmware
between *..5.1.15 - ui/enterprise_network_video_recorder_firmware
between *..5.1.15 - ui/unifi_os_server
between *..5.1.15 - ui/unifi_dream_machine_firmware
between *..5.1.15 - ui/unifi_dream_machine_pro_firmware
between *..5.1.15 - ui/unifi_dream_machine_special_edition_firmware
between *..5.1.15 - ui/unifi_dream_machine_pro_max_firmware
between *..5.1.15 - ui/unifi_dream_machine_beast_firmware
between *..5.1.15 - ui/enterprise_fortress_gateway_firmware
between *..5.1.15 - ui/unifi_dream_router_firmware
between *..5.1.15 - ui/unifi_dream_wall_firmware
between *..5.1.15 - ui/unifi_dream_router_7_firmware
between *..5.1.15 - ui/unifi_express_7_firmware
between *..5.1.15 - ui/unifi_cloudkey_firmware
between *..5.1.15 - ui/unifi_cloud_key_plus_firmware
between *..5.1.15 - ui/unifi_cloudkey_enterprise_firmware
between *..5.1.15 - ui/unifi_network_video_recorder_firmware
between *..5.1.15 - ui/unifi_network_video_recorder_pro_firmware
between *..5.1.15 - ui/unifi_network_video_recorder_instant_firmware
between *..5.1.15 - ui/enterprise_network_video_recorder_core_firmware
between *..5.1.15 - ui/unifi_network_video_recorder_g2_firmware
between *..5.1.15
Description
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.
Affected operating systems
other
ui / enterprise_firewall_core_firmware
other
ui / enterprise_fortress_gateway_firmware
other
ui / enterprise_network_video_recorder_core_firmware
other
ui / enterprise_network_video_recorder_firmware
other
ui / unas_2_firmware
other
ui / unas_4_firmware
other
ui / unas_pro_4_firmware
other
ui / unas_pro_8_firmware
other
ui / unas_pro_firmware
other
ui / unifi_cloud_gateway_fiber_firmware
other
ui / unifi_cloud_gateway_industrial_firmware
other
ui / unifi_cloud_gateway_max_firmware
other
ui / unifi_cloud_gateway_ultra_firmware
other
ui / unifi_cloud_key_plus_firmware
other
ui / unifi_cloudkey_enterprise_firmware
other
ui / unifi_cloudkey_firmware
other
ui / unifi_dream_machine_beast_firmware
other
ui / unifi_dream_machine_firmware
other
ui / unifi_dream_machine_pro_firmware
other
ui / unifi_dream_machine_pro_max_firmware
other
ui / unifi_dream_machine_special_edition_firmware
other
ui / unifi_dream_router_5g_max_firmware
other
ui / unifi_dream_router_7_firmware
other
ui / unifi_dream_router_firmware
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
5.1.15Metrics
Show all metrics
Weakness classes (CWE)
CWE-20Class
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-07-02 16:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-54402","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- New CVE Received2026-07-02 15:17 UTC· support@hackerone.com
- Affected: UniFi OS Server, Dream Machines, Enterprise Fortress Gateway (+9)
- Description: A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.
- CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- CWE: CWE-20