Executive brief
Ubiquiti UniFi OS, the management software for UniFi networking and security hardware, is affected by a security flaw that could allow an attacker to hijack a user's session. If an administrator is logged into their UniFi console and visits a malicious website, the attacker can perform unauthorized actions on the UniFi device as if they were that administrator. This could lead to unauthorized configuration changes, data access, or loss of control over the managed network infrastructure.
Technical details
A Cross-Origin Resource Sharing (CORS) misconfiguration (CWE-942) exists in UniFi OS versions prior to 5.1.19. The vulnerability stems from a permissive cross-domain policy that allows untrusted domains to interact with the UniFi OS API. An attacker can exploit this by luring an authenticated administrator to a malicious webpage, which then executes cross-origin requests to the UniFi OS instance using the victim's active session cookies. Successful exploitation allows the attacker to perform any action the authenticated user is authorized to do, potentially leading to full system compromise. The issue is resolved in UniFi OS version 5.1.19 and later.
Affected products
- Ubiquiti Inc UniFi OS Server < 5.1.19
- Ubiquiti Inc Dream Machines < 5.1.19
- Ubiquiti Inc Enterprise Fortress Gateway < 5.1.19
- Ubiquiti Inc Dream Wall < 5.1.19
- Ubiquiti Inc Dream Routers < 5.1.19
- Ubiquiti Inc Express 7 < 5.1.19
- Ubiquiti Inc Cloud Keys < 5.1.19
- Ubiquiti Inc Network Video Recorders < 5.1.19
- Ubiquiti Inc Enterprise Video Recorders < 5.1.19
- Ubiquiti Inc Cloud Gateways < 5.1.19
- Ubiquiti Inc Network Attached Storage < 5.1.19
- Ubiquiti Inc Enterprise Firewall Core < 5.1.19
Timeline
- 2026-07-02: advisory: Initial advisory published by Ubiquiti and NVD
- 2026-07-02: patched: Fix released in UniFi OS 5.1.19