Junglewise Threat Intelligence

CVE-2026-54405: Ubiquiti UniFi Network Application improper input validation DoS

CVE-2026-54405 · Severity: high · CVSS 7.5 · Published 2026-07-02

Technologies: Ubiquiti UniFi Network Application. Vendors: Ubiquiti, Ubiquiti Inc.

Executive brief

Ubiquiti UniFi Network Application, which is used to manage and configure UniFi networking devices, is vulnerable to a denial-of-service attack. An attacker with network access can exploit this flaw to crash the application or make it unresponsive. This could prevent administrators from managing their network infrastructure or monitoring device status until the service is restored.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Ubiquiti UniFi Network Application. A remote, unauthenticated attacker can exploit this by sending specially crafted network requests to the application. Successful exploitation allows the attacker to trigger a Denial of Service (DoS) condition, impacting the availability of the management interface. The vulnerability is addressed in UniFi Network Application version 10.4.57 and later.

Affected products

  • Ubiquiti Inc UniFi Network Application versions before 10.4.57

Timeline

  • 2026-07-02: advisory
  • 2026-07-02: disclosed

References

Related threats