Executive brief
Ubiquiti UniFi Network Application, a software suite used to manage corporate network infrastructure, is affected by a security flaw in self-hosted installations. An attacker who already has high-level administrative access to the application can bypass directory restrictions to modify files on the underlying server. This could lead to a complete takeover of the host system or significant disruption of network management operations.
Technical details
A path traversal vulnerability (CWE-22) exists in self-hosted instances of Ubiquiti UniFi Network Application. The flaw allows a remote attacker with high-level administrative privileges to bypass intended file system restrictions. By submitting specially crafted input, the attacker can gain unauthorized write access to files on the host operating system. This vulnerability is tracked as CVE-2026-54406 and has been addressed in UniFi Network Application version 10.4.57. The exploit requires network connectivity to the management interface but does not require user interaction beyond the attacker's own actions.
Affected products
- Ubiquiti Inc UniFi Network Application versions before 10.4.57
Timeline
- 2026-07-02: advisory: Ubiquiti published Security Advisory Bulletin 066-066
- 2026-07-02: disclosed: CVE-2026-54406 published to the NVD dataset