A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
An attacker with access to the network where UniFi OS devices operate can exploit improperly implemented access control to perform system operations without required authentication or authorization. The vulnerability does not require user interaction or special privileges, and its scope covers components beyond the directly attacked system (scope: changed). The network vector and lack of prerequisites make the exploit relatively easy to perform from the local network level or potentially broader reach.
An attacker can make unauthorized changes to the configuration or operation of UniFi OS, which may lead to violations of confidentiality, integrity, and availability of the device and the network infrastructure it supports.
Apply patches available from the manufacturer according to the references — detailed patch versions are available in the Ubiquiti security advisory: https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b
Devices running UniFi OS — detailed information about affected versions is indicated in the manufacturer's references (Security Advisory Bulletin 064)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HUi Enterprise Fortress Gateway
HWUiall versionsUi Enterprise Fortress Gateway Firmware
OSUi< 5.1.12Ui Enterprise Network Video Recorder
HWUiall versionsUi Enterprise Network Video Recorder Core
HWUiall versionsUi Enterprise Network Video Recorder Core Firmware
OSUi< 5.1.12Ui Enterprise Network Video Recorder Firmware
OSUi< 5.1.12Ui Unas 2
HWUiall versionsUi Unas 2 Firmware
OSUi< 5.1.10Ui Unas 4
HWUiall versionsUi Unas 4 Firmware
OSUi< 5.1.10Ui Unas Pro
HWUiall versionsUi Unas Pro 4
HWUiall versionsUi Unas Pro 4 Firmware
OSUi< 5.1.10Ui Unas Pro 8
HWUiall versionsUi Unas Pro 8 Firmware
OSUi< 5.1.10Ui Unas Pro Firmware
OSUi< 5.1.10Ui Unifi Cloud Gateway Fiber
HWUiall versionsUi Unifi Cloud Gateway Fiber Firmware
OSUi< 5.1.12Ui Unifi Cloud Gateway Industrial
HWUiall versionsUi Unifi Cloud Gateway Industrial Firmware
OSUi< 5.1.12Ui Unifi Cloud Gateway Max
HWUiall versionsUi Unifi Cloud Gateway Max Firmware
OSUi< 5.1.12Ui Unifi Cloud Gateway Ultra
HWUiall versionsUi Unifi Cloud Gateway Ultra Firmware
OSUi< 5.1.12Ui Unifi Cloudkey
HWUiall versionsUi Unifi Cloudkey Enterprise
HWUiall versionsUi Unifi Cloudkey Enterprise Firmware
OSUi< 5.1.12Ui Unifi Cloudkey Firmware
OSUi< 5.1.12Ui Unifi Cloud Key Plus
HWUiall versionsUi Unifi Cloud Key Plus Firmware
OSUi< 5.1.12
CISA KEV — detailsi
- Vendori
- Ubiquiti
- Producti
- UniFi OS
- Added to KEVi
- June 23, 2026
- Remediation deadline (US Federal)i
- June 26, 2026(overdue)
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.
Related vulnerabilities
Command Injection w UniFi OS via nieprawidłowa walidacja wejścia
Path Traversal w UniFi OS — dostęp do plików systemowych i przejęcie konta
Command Injection w UniFi OS przez błąd walidacji wejścia
Command Injection w UniFi OS — podatność na wstrzyknięcie poleceń
Ubiquiti UniFi Dream Machine Pro — obejście restrykcji domenowych