CVE-2026-54406
Ubiquiti UniFi vulnerability analysis and mitigation

Overview

CVE-2026-54406 is a Path Traversal vulnerability (CWE-22) in self-hosted instances of Ubiquiti's UniFi Network Application that allows a high-privileged, network-authenticated attacker to escalate write permissions on the host device. All versions of UniFi Network Application prior to 10.4.57 are affected; cloud-managed instances are not impacted. The vulnerability was published on July 2, 2026, and a patch was made available shortly thereafter. It carries a CVSS v3.1 base score of 8.7 (High) (GitHub Advisory, Ubiquiti Advisory).

Technical details

The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory), where the UniFi Network Application fails to properly neutralize path traversal sequences (e.g., ../) in user-supplied input used to construct file system paths. An authenticated attacker with high privileges can craft requests that resolve to file system locations outside the application's intended restricted directory, enabling arbitrary file writes on the host. The attack vector is network-based, requires no user interaction, and has a changed scope — meaning the impact extends beyond the vulnerable component itself to the underlying host OS. No public proof-of-concept exploit code has been identified at this time (GitHub Advisory, Ubiquiti Advisory).

Impact

Successful exploitation allows a high-privileged attacker to write arbitrary files to locations outside the application's intended directory on the host device, effectively escalating their write permissions beyond the application sandbox. This can lead to modification of critical system files, planting of malicious scripts or backdoors, and potential full host compromise. Availability and integrity of the host are both rated High impact, while confidentiality is not directly affected by this vulnerability. The changed scope indicates that exploitation can affect resources beyond the UniFi application itself, including the underlying operating system (GitHub Advisory, Ubiquiti Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code as of the time of reporting. The EPSS score is approximately 0.325%, indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high privileges and network access, which limits the attacker pool but does not eliminate risk in environments with compromised or malicious administrators (GitHub Advisory, Ubiquiti Advisory).

Indicators of compromise

  • Logs: Unexpected file write operations logged outside the UniFi application's data directory (e.g., /usr/lib/unifi/ or configured data path); application logs showing unusual file path parameters containing ../ or URL-encoded traversal sequences.
  • File System: Presence of unexpected or newly created files in system directories (e.g., /etc/, /tmp/, /var/) that are not associated with normal UniFi operation; modification timestamps on system files coinciding with UniFi application activity.
  • Process: Unusual processes spawned from the UniFi application process (e.g., java) that interact with system-level files or directories outside the application's normal scope.
  • Network: Anomalous authenticated API or web requests to the UniFi Network Application containing path traversal patterns (../, %2e%2e%2f, %252e%252e%252f) in file-related parameters.

Mitigation and workarounds

Ubiquiti has released UniFi Network Application version 10.4.57, which addresses this vulnerability; administrators should upgrade immediately (Ubiquiti Advisory). As interim mitigations, restrict network access to the UniFi Network Application administrative interface to trusted IP ranges only, and limit high-privilege account access to only those administrators who require it. Implement file integrity monitoring on the host device to detect unauthorized file modifications, and consider network segmentation to isolate UniFi instances from critical infrastructure.

Community reactions

Ubiquiti disclosed this vulnerability as part of Security Advisory Bulletin 066, which covered 25 security vulnerabilities across the UniFi ecosystem, drawing coverage from cybersecurity news outlets (CyberSecurityNews, Cryptika). Field Effect published a blog post noting Ubiquiti's patching of multiple critical vulnerabilities in UniFi products (Field Effect). Community reaction has been moderate, with the disclosure noted across security aggregators and social platforms, but no significant controversy or researcher-published technical deep-dives have emerged at this time.

Additional resources


SourceThis report was generated using AI

Related Ubiquiti UniFi vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55114HIGH8.8
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesJul 02, 2026
CVE-2026-54406HIGH8.7
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesJul 02, 2026
CVE-2026-55118HIGH8.3
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesJul 02, 2026
CVE-2026-56842HIGH7.5
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesJul 02, 2026
CVE-2026-54405HIGH7.5
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesJul 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management