Executive brief
A critical security vulnerability has been identified in Ubiquiti UniFi OS, the software used to manage UniFi networking and security devices. An attacker with network access can bypass security restrictions to read or modify sensitive system files. This could allow them to take full control of the device and its associated accounts, potentially compromising the entire managed network.
Technical details
A path traversal vulnerability (CWE-22) exists in multiple Ubiquiti UniFi OS devices. The flaw allows an unauthenticated attacker with network access to the device to bypass directory restrictions and access sensitive files on the underlying operating system. By manipulating these files, an attacker can escalate privileges or gain unauthorized access to system accounts. The vulnerability is rated critical with a CVSS score of 10.0 due to its potential for full system compromise. Patches have been released for various product lines, including UniFi OS Server (v5.0.8), Express (v4.0.14), and the UDM series (v5.1.12).
Affected products
- Ubiquiti UniFi OS Server < 5.0.8
- Ubiquiti Express < 4.0.14
- Ubiquiti UDM / UDM-Pro / UDM-SE / UDM-Pro-Max / EFG / UDW / UDR / UDR7 / UDR-5G < 5.1.12
- Ubiquiti UDM-Beast < 5.1.11
Timeline
- 2026-05-21: disclosed: Initial disclosure by HackerOne
- 2026-05-21: advisory: NVD Published Date
- 2026-06-23: other: Advisory publication date provided in report