CVE-2026-54405
Ubiquiti UniFi vulnerability analysis and mitigation

Overview

CVE-2026-54405 is an Improper Input Validation vulnerability in Ubiquiti's UniFi Network Application that allows a network-adjacent or remote unauthenticated attacker to execute a Denial of Service (DoS) attack against the application. It affects all versions of UniFi Network Application prior to 10.4.57. The vulnerability was published on July 2, 2026, and was reported via HackerOne. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Ubiquiti Advisory).

Technical details

The root cause is classified as CWE-20 (Improper Input Validation), meaning the UniFi Network Application fails to adequately validate or sanitize certain network-supplied input before processing it. An unauthenticated attacker with network access can send specially crafted malicious input to the application, triggering a crash or making the service unavailable. No authentication, user interaction, or elevated privileges are required, and the attack complexity is low, making it straightforward to automate (GitHub Advisory, Ubiquiti Advisory). No public technical write-up or proof-of-concept code has been identified at this time.

Impact

Successful exploitation results in a Denial of Service condition, causing the UniFi Network Application to crash or become unavailable to legitimate users and administrators. There is no impact on confidentiality or data integrity — the vulnerability is limited to availability. Organizations relying on UniFi Network Application for network management could experience loss of visibility and control over their network infrastructure during an attack (GitHub Advisory, Ubiquiti Advisory).

Exploitability

As of the time of reporting, there is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.263% (18th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The NVD SSVC assessment classifies the vulnerability as automatable with no known exploitation (Ubiquiti Advisory).

Indicators of compromise

  • Network: Unusual or high-volume traffic directed at the UniFi Network Application's management port(s) from unexpected source IPs; repeated malformed or oversized requests to the application's API or web interface.
  • Logs: Application logs showing repeated errors, exceptions, or crash reports around input processing; sudden service restarts or unresponsive states logged by the UniFi Network Application.
  • Process: Unexpected termination or restart of the UniFi Network Application process (e.g., unifi service stopping and restarting repeatedly on the host system).

Mitigation and workarounds

Ubiquiti has released UniFi Network Application version 10.4.57 as the patched release; all users should upgrade to this version or later (Ubiquiti Advisory). As interim mitigations, administrators should restrict network access to the UniFi Network Application to trusted networks and management VLANs only, implement rate limiting on the application's exposed ports, and monitor for unusual traffic patterns indicative of DoS attempts. Applying the vendor update is the definitive remediation.

Community reactions

CVE-2026-54405 was part of a broader disclosure by Ubiquiti covering 25 security vulnerabilities across the UniFi ecosystem, which received coverage from several cybersecurity news outlets including CyberSecurityNews, CyberPress, and SecurityOnline (CyberSecurityNews, SecurityOnline). Field Effect also published a blog post noting Ubiquiti's patching of multiple critical vulnerabilities in UniFi products (Field Effect). General community reaction has been moderate given the DoS-only impact and absence of public exploits.

Additional resources


SourceThis report was generated using AI

Related Ubiquiti UniFi vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55114HIGH8.8
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesJul 02, 2026
CVE-2026-54406HIGH8.7
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesJul 02, 2026
CVE-2026-55118HIGH8.3
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesJul 02, 2026
CVE-2026-56842HIGH7.5
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesJul 02, 2026
CVE-2026-54405HIGH7.5
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesJul 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management