CVE-2026-47369: Input Validation

Published Jun 12, 2026
·
Updated

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.

Affected Software

1 affected component
Ubiquiti UniFi OS

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Disable or restrict remote/management access for low-privilege accounts and unnecessary network-facing services; enforce least-privilege for local accounts and limit which IP ranges can reach UniFi OS management interfaces.

    UniFi OS management/remote access = restricted to trusted IPs or disabled for unneeded accounts
  2. Compensating control

    Restrict network access to UniFi OS devices and instances: place devices on a management VLAN, apply firewall/ACL rules to allow management only from trusted IPs/networks, and block or limit access from untrusted networks (including the Internet).

Event History

Jun 12, 2026
CVE Published
via MITRE·02:27 AM
Data Sourced
via MITRE·02:27 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-47369?

The severity of CVE-2026-47369 is critical with a score of 9.9.

2

How do I fix CVE-2026-47369?

To fix CVE-2026-47369, ensure that you apply the latest security updates provided by Ubiquiti for UniFi OS.

3

What types of privileges can be escalated due to CVE-2026-47369?

CVE-2026-47369 allows a malicious actor to escalate privileges from low to higher levels within UniFi OS devices.

4

What impact does CVE-2026-47369 have on data security?

CVE-2026-47369 can lead to unauthorized access to sensitive data due to improper input validation.

5

Who is affected by CVE-2026-47369?

CVE-2026-47369 affects devices running UniFi OS that are accessible over networks where an attacker has low privileges.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203