Executive brief
Ubiquiti UniFi OS devices, which manage networking and security hardware, are vulnerable to a security flaw that allows an authorized user with low-level access to gain higher administrative privileges. By exploiting this flaw, an attacker could potentially take control of the device or access sensitive configuration data. This affects various UniFi hardware including Dream Machines, Cloud Keys, and Video Recorders.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability (CWE-918) exists in Ubiquiti UniFi OS across multiple hardware platforms. An attacker with network connectivity and valid low-privileged credentials can trigger the vulnerability to make unauthorized requests from the server's perspective. This can be leveraged to bypass internal security controls and achieve privilege escalation within the UniFi OS environment. The vulnerability is addressed in UniFi OS version 5.1.19 and later.
Affected products
- Ubiquiti Inc UniFi OS Server < 5.1.19
- Ubiquiti Inc Dream Machines < 5.1.19
- Ubiquiti Inc Enterprise Fortress Gateway < 5.1.19
- Ubiquiti Inc Dream Wall < 5.1.19
- Ubiquiti Inc Dream Routers < 5.1.19
- Ubiquiti Inc Express 7 < 5.1.19
- Ubiquiti Inc Cloud Keys < 5.1.19
- Ubiquiti Inc Network Video Recorders < 5.1.19
- Ubiquiti Inc Enterprise Video Recorders < 5.1.19
- Ubiquiti Inc Cloud Gateways < 5.1.19
- Ubiquiti Inc Network Attached Storage < 5.1.19
- Ubiquiti Inc Enterprise Firewall Core < 5.1.19
Timeline
- 2026-07-02: disclosed
- 2026-07-02: advisory