Vulnerabilities (CVE)

Filtered by vendor Ui Subscribe
Filtered by product Unifi Network Application
Total 9 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-54406 1 Ui 1 Unifi Network Application 2026-07-06 N/A 8.7 HIGH
A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi Network Application to escalate write permission on the host device.
CVE-2026-55114 1 Ui 1 Unifi Network Application 2026-07-06 N/A 8.8 HIGH
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.
CVE-2026-56842 1 Ui 1 Unifi Network Application 2026-07-06 N/A 7.5 HIGH
A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Network Application to persist privileges within UniFi Network Application after such access had been removed.
CVE-2026-55118 1 Ui 1 Unifi Network Application 2026-07-06 N/A 8.3 HIGH
A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.
CVE-2026-54405 1 Ui 1 Unifi Network Application 2026-07-02 N/A 7.5 HIGH
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Denial of Service (DoS) attack on the application.
CVE-2024-42025 1 Ui 1 Unifi Network Application 2026-06-17 N/A 7.8 HIGH
A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.3.32 and earlier) allows a malicious actor with unifi user shell access to escalate privileges to root on the host device.
CVE-2023-41721 1 Ui 6 Unifi Dream Machine, Unifi Dream Machine Pro, Unifi Dream Machine Special Edition and 3 more 2026-06-17 N/A 5.3 MEDIUM
Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a risk of access to device configuration information by a malicious actor with preexisting access to the network. Affected Products: UDM UDM-PRO UDM-SE UDR UDW Mitigation: Update UniFi Network to Version 7.5.187 or later.
CVE-2023-32000 1 Ui 1 Unifi Network Application 2026-06-17 N/A 4.8 MEDIUM
A Cross-Site Scripting (XSS) vulnerability found in UniFi Network (Version 7.3.83 and earlier) allows a malicious actor with Site Administrator credentials to escalate privileges by persuading an Administrator to visit a malicious web page.
CVE-2023-28365 2 Linux, Ui 2 Linux Kernel, Unifi Network Application 2026-06-17 N/A 9.1 CRITICAL
A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems allows application administrators to execute malicious commands on the host device being restored.