CVE-2026-95861
UniFi: Uncontrolled Recursion (CVE-2026-95861)
highEPSS 0.5%
Description
A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
UbiquitiUniFi
Gateways <5.1.26Metrics
Show all metrics
Severity
high
79.02
no public PoC known
7.5
Published
2026-09-22 18:47 UTC
CWE-674
Weakness classes (CWE)
CWE-674Class
Uncontrolled Recursion
The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-09-22 20:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-95861","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
- New CVE Received2026-09-22 19:17 UTC· fe490ce8-0395-4072-90d8-2707e1bdf984
- Description: A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CWE: CWE-674
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/95xxx/CVE-2026-95861.json">CVE-2026-95861</a>