Junglewise Threat Intelligence

CVE-2026-54401: Ubiquiti UniFi OS SSRF privilege escalation

CVE-2026-54401 · Severity: high · CVSS 7.7 · Published 2026-07-02

Technologies: Ubiquiti Enterprise Firewall Core, Ubiquiti Network Video Recorder, Ubiquiti Inc Network Attached Storage, Ubiquiti Dream Router, Ubiquiti Dream Machine, Ubiquiti Enterprise Video Recorder, Ubiquiti Cloud Gateway, Ubiquiti UniFi OS, Ubiquiti Cloud Key, Ubiquiti Dream Wall. Vendors: Ubiquiti, Ubiquiti Inc.

Executive brief

Ubiquiti UniFi OS devices, which manage networking and security hardware, are vulnerable to a security flaw that allows an authorized user with low-level access to gain higher administrative privileges. By exploiting this flaw, an attacker could potentially take control of the device or access sensitive configuration data. This affects various UniFi hardware including Dream Machines, Cloud Keys, and Video Recorders.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability (CWE-918) exists in Ubiquiti UniFi OS across multiple hardware platforms. An attacker with network connectivity and valid low-privileged credentials can trigger the vulnerability to make unauthorized requests from the server's perspective. This can be leveraged to bypass internal security controls and achieve privilege escalation within the UniFi OS environment. The vulnerability is addressed in UniFi OS version 5.1.19 and later.

Affected products

  • Ubiquiti Inc UniFi OS Server < 5.1.19
  • Ubiquiti Inc Dream Machines < 5.1.19
  • Ubiquiti Inc Enterprise Fortress Gateway < 5.1.19
  • Ubiquiti Inc Dream Wall < 5.1.19
  • Ubiquiti Inc Dream Routers < 5.1.19
  • Ubiquiti Inc Express 7 < 5.1.19
  • Ubiquiti Inc Cloud Keys < 5.1.19
  • Ubiquiti Inc Network Video Recorders < 5.1.19
  • Ubiquiti Inc Enterprise Video Recorders < 5.1.19
  • Ubiquiti Inc Cloud Gateways < 5.1.19
  • Ubiquiti Inc Network Attached Storage < 5.1.19
  • Ubiquiti Inc Enterprise Firewall Core < 5.1.19

Timeline

  • 2026-07-02: disclosed
  • 2026-07-02: advisory

References

Related threats