ZeroHour

CVE-2026-54401

CVSS 3.1
8.8 high
EPSS
<1%p36
Published
()
Modified
Description

A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances.

Vendors
ui
Products
unifi os server, unifi dream machine firmware, unifi dream machine pro firmware, unifi dream machine special edition firmware, unifi dream machine pro max firmware, unifi dream machine beast firmware, enterprise fortress gateway firmware, unifi dream router firmware, unifi dream wall firmware, unifi dream router 7 firmware, unifi express 7 firmware, unifi cloudkey firmware
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.