PT-2026-55237 · Ubiquiti+1 · Cloud Gateways+41
CVE-2026-54401
·
Published
2026-07-02
·
Updated
2026-07-10
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UniFi OS (affected versions not specified)
Description
A Server-Side Request Forgery (SSRF) allows a malicious actor with low privileges and network access to escalate privileges within the system. SSRF is a flaw where an attacker can induce the server-side application to make requests to an unintended location.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloud Gateways
Cloud Keys
Dream Machines
Dream Routers
Dream Wall
Enterprise Firewall Core
Enterprise Fortress Gateway
Enterprise Video Recorders
Express 7
Network Attached Storage
Network Video Recorders
Unifi Os Server
Enterprise Firewall Core Firmware
Enterprise Fortress Gateway Firmware
Enterprise Network Video Recorder Core Firmware
Enterprise Network Video Recorder Firmware
Unas 2 Firmware
Unas 4 Firmware
Unas Pro 4 Firmware
Unas Pro 8 Firmware
Unas Pro Firmware
Unifi Cloud Gateway Fiber Firmware
Unifi Cloud Gateway Industrial Firmware
Unifi Cloud Gateway Max Firmware
Unifi Cloud Gateway Ultra Firmware
Unifi Cloud Key Plus Firmware
Unifi Cloudkey Enterprise Firmware
Unifi Cloudkey Firmware
Unifi Dream Machine Beast Firmware
Unifi Dream Machine Pro Firmware
Unifi Dream Machine Pro Max Firmware
Unifi Dream Machine Special Edition Firmware
Unifi Dream Router 5G Max Firmware
Unifi Dream Router 7 Firmware
Unifi Dream Router Firmware
Unifi Dream Wall Firmware
Unifi Express 7 Firmware
Unifi Network Video Recorder Firmware
Unifi Network Video Recorder G2 Firmware
Unifi Network Video Recorder G2 Pro Firmware
Unifi Network Video Recorder Instant Firmware
Unifi Network Video Recorder Pro Firmware