CVE-2026-54402: Input Validation
Published Jul 2, 2026
·Updated
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.
Affected Software
64 affected components
Ubiquiti UniFi OS
UI Unifi Os Server<=5.1.15
All of the following
UI Unifi Dream Machine Firmware<=5.1.15
UI Unifi Dream Machine
All of the following
UI Unifi Dream Machine Pro Firmware<=5.1.15
UI UniFi Dream Machine Pro
All of the following
UI Unifi Dream Machine Special Edition Firmware<=5.1.15
UI Unifi Dream Machine Special Edition
All of the following
UI Unifi Dream Machine Pro Max Firmware<=5.1.15
UI Unifi Dream Machine Pro Max
All of the following
UI Unifi Dream Machine Beast Firmware<=5.1.15
UI Unifi Dream Machine Beast
All of the following
UI Enterprise Fortress Gateway Firmware<=5.1.15
UI Enterprise Fortress Gateway
All of the following
UI Unifi Dream Router Firmware<=5.1.15
UI Unifi Dream Router
All of the following
UI Unifi Dream Wall Firmware<=5.1.15
UI Unifi Dream Wall
All of the following
UI Unifi Dream Router 7 Firmware<=5.1.15
UI Unifi Dream Router 7
All of the following
UI Unifi Express 7 Firmware<=5.1.15
UI Unifi Express 7
All of the following
UI Unifi Cloudkey Firmware<=5.1.15
UI Unifi Cloudkey
All of the following
UI Unifi Cloud Key Plus Firmware<=5.1.15
UI Unifi Cloud Key Plus
All of the following
UI Unifi Cloudkey Enterprise Firmware<=5.1.15
UI Unifi Cloudkey Enterprise
All of the following
UI Unifi Network Video Recorder Firmware<=5.1.15
UI Unifi Network Video Recorder
All of the following
UI Unifi Network Video Recorder Pro Firmware<=5.1.15
UI Unifi Network Video Recorder Pro
All of the following
UI Unifi Network Video Recorder Instant Firmware<=5.1.15
UI Unifi Network Video Recorder Instant
All of the following
UI Enterprise Network Video Recorder Core Firmware<=5.1.15
UI Enterprise Network Video Recorder Core
All of the following
UI Unifi Network Video Recorder G2 Firmware<=5.1.15
UI Unifi Network Video Recorder G2
All of the following
UI Unifi Network Video Recorder G2 Pro Firmware<=5.1.15
UI Unifi Network Video Recorder G2 Pro
All of the following
UI Unifi Cloud Gateway Ultra Firmware<=5.1.15
UI Unifi Cloud Gateway Ultra
All of the following
UI Unifi Cloud Gateway Max Firmware<=5.1.15
UI Unifi Cloud Gateway Max
All of the following
UI Unifi Cloud Gateway Industrial Firmware<=5.1.15
UI Unifi Cloud Gateway Industrial
All of the following
UI Unifi Cloud Gateway Fiber Firmware<=5.1.15
UI Unifi Cloud Gateway Fiber
All of the following
UI Unas 2 Firmware<=5.1.16
UI Unas 2
All of the following
UI Unas 4 Firmware<=5.1.16
UI Unas 4
All of the following
UI Unas Pro Firmware<=5.1.16
UI Unas Pro
All of the following
UI Unas Pro 4 Firmware<=5.1.16
UI Unas Pro 4
All of the following
UI Unas Pro 8 Firmware<=5.1.16
UI Unas Pro 8
All of the following
UI Enterprise Firewall Core Firmware<=5.1.18
UI Enterprise Firewall Core
All of the following
UI Unifi Dream Router 5g Max Firmware<=5.1.15
UI Unifi Dream Router 5g Max
All of the following
UI Enterprise Network Video Recorder Firmware<=5.1.15
UI Enterprise Network Video Recorder
Event History
Jul 2, 2026
CVE Published
via MITRE·02:49 PM
Data Sourced
via MITRE·02:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeaknessAffected Software
Jul 8, 2026
News Published
via BleepingComputer·08:15 AM
News Published
via BleepingComputer·08:16 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-54402?
The severity of CVE-2026-54402 is critical, with a CVSS score of 9.9.
2
How do I fix CVE-2026-54402?
To fix CVE-2026-54402, update Ubiquiti UniFi OS to the latest version that addresses the improper input validation vulnerability.
3
What type of vulnerability is CVE-2026-54402?
CVE-2026-54402 is an Improper Input Validation vulnerability that allows for Command Injection.
4
Who is affected by CVE-2026-54402?
Any user of Ubiquiti UniFi OS with a network access and low privileges could be affected by CVE-2026-54402.
5
What are the potential impacts of exploiting CVE-2026-54402?
Exploitation of CVE-2026-54402 could lead to complete system compromise, including unauthorized command execution.