CVE-2026-54402

unifi_os_server: Improper Input Validation (CVE-2026-54402)

criticalEPSS 1.8%

Affected

  • ui/unifi_network_video_recorder_g2_pro_firmware between *..5.1.15
  • ui/unifi_cloud_gateway_ultra_firmware between *..5.1.15
  • ui/unifi_cloud_gateway_max_firmware between *..5.1.15
  • ui/unifi_cloud_gateway_industrial_firmware between *..5.1.15
  • ui/unifi_cloud_gateway_fiber_firmware between *..5.1.15
  • ui/unas_2_firmware between *..5.1.16
  • ui/unas_4_firmware between *..5.1.16
  • ui/unas_pro_firmware between *..5.1.16
  • ui/unas_pro_4_firmware between *..5.1.16
  • ui/unas_pro_8_firmware between *..5.1.16
  • ui/enterprise_firewall_core_firmware between *..5.1.18
  • ui/unifi_dream_router_5g_max_firmware between *..5.1.15
  • ui/enterprise_network_video_recorder_firmware between *..5.1.15
  • ui/unifi_os_server between *..5.1.15
  • ui/unifi_dream_machine_firmware between *..5.1.15
  • ui/unifi_dream_machine_pro_firmware between *..5.1.15
  • ui/unifi_dream_machine_special_edition_firmware between *..5.1.15
  • ui/unifi_dream_machine_pro_max_firmware between *..5.1.15
  • ui/unifi_dream_machine_beast_firmware between *..5.1.15
  • ui/enterprise_fortress_gateway_firmware between *..5.1.15
  • ui/unifi_dream_router_firmware between *..5.1.15
  • ui/unifi_dream_wall_firmware between *..5.1.15
  • ui/unifi_dream_router_7_firmware between *..5.1.15
  • ui/unifi_express_7_firmware between *..5.1.15
  • ui/unifi_cloudkey_firmware between *..5.1.15
  • ui/unifi_cloud_key_plus_firmware between *..5.1.15
  • ui/unifi_cloudkey_enterprise_firmware between *..5.1.15
  • ui/unifi_network_video_recorder_firmware between *..5.1.15
  • ui/unifi_network_video_recorder_pro_firmware between *..5.1.15
  • ui/unifi_network_video_recorder_instant_firmware between *..5.1.15
  • ui/enterprise_network_video_recorder_core_firmware between *..5.1.15
  • ui/unifi_network_video_recorder_g2_firmware between *..5.1.15

Description

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.

Affected operating systems

  • other

    ui / enterprise_firewall_core_firmware

  • other

    ui / enterprise_fortress_gateway_firmware

  • other

    ui / enterprise_network_video_recorder_core_firmware

  • other

    ui / enterprise_network_video_recorder_firmware

  • other

    ui / unas_2_firmware

  • other

    ui / unas_4_firmware

  • other

    ui / unas_pro_4_firmware

  • other

    ui / unas_pro_8_firmware

  • other

    ui / unas_pro_firmware

  • other

    ui / unifi_cloud_gateway_fiber_firmware

  • other

    ui / unifi_cloud_gateway_industrial_firmware

  • other

    ui / unifi_cloud_gateway_max_firmware

  • other

    ui / unifi_cloud_gateway_ultra_firmware

  • other

    ui / unifi_cloud_key_plus_firmware

  • other

    ui / unifi_cloudkey_enterprise_firmware

  • other

    ui / unifi_cloudkey_firmware

  • other

    ui / unifi_dream_machine_beast_firmware

  • other

    ui / unifi_dream_machine_firmware

  • other

    ui / unifi_dream_machine_pro_firmware

  • other

    ui / unifi_dream_machine_pro_max_firmware

  • other

    ui / unifi_dream_machine_special_edition_firmware

  • other

    ui / unifi_dream_router_5g_max_firmware

  • other

    ui / unifi_dream_router_7_firmware

  • other

    ui / unifi_dream_router_firmware

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

uiunifi_os_server
5.1.15

Metrics

9.9
Source: cna-v3
77.3 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
1.8 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-07-02 15:17 UTC
CWE-20

Weakness classes (CWE)

  • CWE-20Class

    Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-07-02 16:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-54402","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  2. New CVE Received2026-07-02 15:17 UTC· support@hackerone.com
    • Affected: UniFi OS Server, Dream Machines, Enterprise Fortress Gateway (+9)
    • Description: A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.
    • CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
    • CWE: CWE-20

Linked advisories