CVE-2026-54404

Published Jul 2, 2026

Last updated 17 days ago

Overview

Description
A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to escalate privileges within such UniFi OS devices or instances.
Source
support@hackerone.com
NVD status
Analyzed
Products
unifi_dream_machine_beast_firmware, enterprise_fortress_gateway_firmware, unifi_dream_router_firmware, unifi_dream_wall_firmware, unifi_dream_router_7_firmware, unifi_express_7_firmware, unifi_cloudkey_firmware, unifi_cloud_key_plus_firmware, unifi_cloudkey_enterprise_firmware, unifi_network_video_recorder_firmware, unifi_network_video_recorder_pro_firmware, unifi_network_video_recorder_instant_firmware, enterprise_network_video_recorder_firmware, enterprise_network_video_recorder_core_firmware, unifi_network_video_recorder_g2_firmware, unifi_network_video_recorder_g2_pro_firmware, unifi_cloud_gateway_ultra_firmware, unifi_cloud_gateway_max_firmware, unifi_cloud_gateway_industrial_firmware, unifi_cloud_gateway_fiber_firmware, unas_2_firmware, unas_4_firmware, unas_pro_firmware, unas_pro_4_firmware, unas_pro_8_firmware, enterprise_firewall_core_firmware, unifi_os_server, unifi_dream_machine_firmware, unifi_dream_machine_pro_firmware, unifi_dream_machine_special_edition_firmware, unifi_dream_machine_pro_max_firmware, unifi_dream_router_5g_max_firmware

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

support@hackerone.com
CWE-89

Social media

Hype score
Not currently trending

Configurations