CVE-2026-54401Disclosure(ui / enterprise_firewall_core)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_firewall_core
  • enterprise_firewall_core_firmware
  • enterprise_fortress_gateway
  • enterprise_fortress_gateway_firmware

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-07-02); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
enterprise_firewall_coreenterprise_firewall_core_firmwareenterprise_fortress_gatewayenterprise_fortress_gateway_firmwareenterprise_network_video_recorderenterprise_network_video_recorder_coreenterprise_network_video_recorder_core_firmwareenterprise_network_video_recorder_firmwareunas_2unas_2_firmware

1 version affected across 63 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-02: 1Mentions · 2026-07-10: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-10: 107-0207-10
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-54401 Server-Side Request Forgery Privilege Escalation in UniFi OS Devices https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-54401

    Post summary

    A new vulnerability (CVE‑2026‑54401) is disclosed, detailing a server‑side request forgery that allows privilege escalation on UniFi OS devices.

    01010126
    4.1K followersView on X
  • DFIR Lab@DFIR_Lab
    Disclosure

    🚨 HIGH SEVERITY: CVE-2026-54401 (CVSS 7.7) SSRF vulnerability in UniFi OS devices allows privilege escalation with low-privilege network access. Impact: High confidentiality breach CWE-918 #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR https://t.co/x64KDc2anS

    Post summary

    The post announces a newly disclosed SSRF vulnerability in UniFi OS devices with associated CVSS score and technical details, but does not provide evidence of exploitation, patching, or a proof‑of‑concept.

    1000066
    71 followersView on X
CPE platform detail63 entries

63 of 63 entries

PartVendorProductVersionTarget SWTarget HW
HWuienterprise_firewall_core---
OSuienterprise_firewall_core_firmware---
HWuienterprise_fortress_gateway---
OSuienterprise_fortress_gateway_firmware---
HWuienterprise_network_video_recorder---
HWuienterprise_network_video_recorder_core---
OSuienterprise_network_video_recorder_core_firmware---
OSuienterprise_network_video_recorder_firmware---
HWuiunas_2---
OSuiunas_2_firmware---
HWuiunas_4---
OSuiunas_4_firmware---
HWuiunas_pro---
HWuiunas_pro_4---
OSuiunas_pro_4_firmware---
HWuiunas_pro_8---
OSuiunas_pro_8_firmware---
OSuiunas_pro_firmware---
HWuiunifi_cloud_gateway_fiber---
OSuiunifi_cloud_gateway_fiber_firmware---
HWuiunifi_cloud_gateway_industrial---
OSuiunifi_cloud_gateway_industrial_firmware---
HWuiunifi_cloud_gateway_max---
OSuiunifi_cloud_gateway_max_firmware---
HWuiunifi_cloud_gateway_ultra---
OSuiunifi_cloud_gateway_ultra_firmware---
HWuiunifi_cloud_key_plus---
OSuiunifi_cloud_key_plus_firmware---
HWuiunifi_cloudkey---
HWuiunifi_cloudkey_enterprise---
OSuiunifi_cloudkey_enterprise_firmware---
OSuiunifi_cloudkey_firmware---
HWuiunifi_dream_machine---
HWuiunifi_dream_machine_beast---
OSuiunifi_dream_machine_beast_firmware---
OSuiunifi_dream_machine_firmware---
HWuiunifi_dream_machine_pro---
OSuiunifi_dream_machine_pro_firmware---
HWuiunifi_dream_machine_pro_max---
OSuiunifi_dream_machine_pro_max_firmware---
HWuiunifi_dream_machine_special_edition---
OSuiunifi_dream_machine_special_edition_firmware---
HWuiunifi_dream_router---
HWuiunifi_dream_router_5g_max---
OSuiunifi_dream_router_5g_max_firmware---
HWuiunifi_dream_router_7---
OSuiunifi_dream_router_7_firmware---
OSuiunifi_dream_router_firmware---
HWuiunifi_dream_wall---
OSuiunifi_dream_wall_firmware---
HWuiunifi_express_7---
OSuiunifi_express_7_firmware---
HWuiunifi_network_video_recorder---
OSuiunifi_network_video_recorder_firmware---
HWuiunifi_network_video_recorder_g2---
OSuiunifi_network_video_recorder_g2_firmware---
HWuiunifi_network_video_recorder_g2_pro---
OSuiunifi_network_video_recorder_g2_pro_firmware---
HWuiunifi_network_video_recorder_instant---
OSuiunifi_network_video_recorder_instant_firmware---
HWuiunifi_network_video_recorder_pro---
OSuiunifi_network_video_recorder_pro_firmware---
Appuiunifi_os_server---

Explore more