Skip to content
CodeAuditAgent

CVE-2026-54404

A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to escalate privileges within such UniFi OS devices or instances.

Weakness

A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to escalate privileges within such UniFi OS devices or instances.

Affected products

  • ui unifi_dream_machine_beast_firmware
  • ui unifi_dream_machine_beast
  • ui enterprise_fortress_gateway_firmware
  • ui enterprise_fortress_gateway
  • ui unifi_dream_router_firmware
  • ui unifi_dream_router
  • ui unifi_dream_wall_firmware
  • ui unifi_dream_wall

References

Find the bug before an attacker does.

Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.