CVE-2026-54404: SQL Injection

Published Jul 2, 2026
·
Updated

A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to escalate privileges within such UniFi OS devices or instances.

Affected Software

64 affected components
Ubiquiti UniFi OS
All of the following
UI Unifi Dream Machine Beast Firmware<=5.1.15
UI Unifi Dream Machine Beast
All of the following
UI Enterprise Fortress Gateway Firmware<=5.1.15
UI Enterprise Fortress Gateway
All of the following
UI Unifi Dream Router Firmware<=5.1.15
UI Unifi Dream Router
All of the following
UI Unifi Dream Wall Firmware<=5.1.15
UI Unifi Dream Wall
All of the following
UI Unifi Dream Router 7 Firmware<=5.1.15
UI Unifi Dream Router 7
All of the following
UI Unifi Express 7 Firmware<=5.1.15
UI Unifi Express 7
All of the following
UI Unifi Cloudkey Firmware<=5.1.15
UI Unifi Cloudkey
All of the following
UI Unifi Cloud Key Plus Firmware<=5.1.15
UI Unifi Cloud Key Plus
All of the following
UI Unifi Cloudkey Enterprise Firmware<=5.1.15
UI Unifi Cloudkey Enterprise
All of the following
UI Unifi Network Video Recorder Firmware<=5.1.15
UI Unifi Network Video Recorder
All of the following
UI Unifi Network Video Recorder Pro Firmware<=5.1.15
UI Unifi Network Video Recorder Pro
All of the following
UI Unifi Network Video Recorder Instant Firmware<=5.1.15
UI Unifi Network Video Recorder Instant
All of the following
UI Enterprise Network Video Recorder Firmware<=5.1.15
UI Enterprise Network Video Recorder
All of the following
UI Enterprise Network Video Recorder Core Firmware<=5.1.15
UI Enterprise Network Video Recorder Core
All of the following
UI Unifi Network Video Recorder G2 Firmware<=5.1.15
UI Unifi Network Video Recorder G2
All of the following
UI Unifi Network Video Recorder G2 Pro Firmware<=5.1.15
UI Unifi Network Video Recorder G2 Pro
All of the following
UI Unifi Cloud Gateway Ultra Firmware<=5.1.15
UI Unifi Cloud Gateway Ultra
All of the following
UI Unifi Cloud Gateway Max Firmware<=5.1.15
UI Unifi Cloud Gateway Max
All of the following
UI Unifi Cloud Gateway Industrial Firmware<=5.1.15
UI Unifi Cloud Gateway Industrial
All of the following
UI Unifi Cloud Gateway Fiber Firmware<=5.1.15
UI Unifi Cloud Gateway Fiber
All of the following
UI Unas 2 Firmware<=5.1.16
UI Unas 2
All of the following
UI Unas 4 Firmware<=5.1.16
UI Unas 4
All of the following
UI Unas Pro Firmware<=5.1.16
UI Unas Pro
All of the following
UI Unas Pro 4 Firmware<=5.1.16
UI Unas Pro 4
All of the following
UI Unas Pro 8 Firmware<=5.1.16
UI Unas Pro 8
All of the following
UI Enterprise Firewall Core Firmware<=5.1.18
UI Enterprise Firewall Core
UI Unifi Os Server<=5.1.15
All of the following
UI Unifi Dream Machine Firmware<=5.1.15
UI Unifi Dream Machine
All of the following
UI Unifi Dream Machine Pro Firmware<=5.1.15
UI UniFi Dream Machine Pro
All of the following
UI Unifi Dream Machine Special Edition Firmware<=5.1.15
UI Unifi Dream Machine Special Edition
All of the following
UI Unifi Dream Machine Pro Max Firmware<=5.1.15
UI Unifi Dream Machine Pro Max
All of the following
UI Unifi Dream Router 5g Max Firmware<=5.1.15
UI Unifi Dream Router 5g Max

Event History

Jul 2, 2026
CVE Published
via MITRE·02:49 PM
Data Sourced
via MITRE·02:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-54404?

CVE-2026-54404 has a severity rating of 8.8, indicating a high risk level.

2

How do I fix CVE-2026-54404?

To fix CVE-2026-54404, ensure that your Ubiquiti UniFi OS is updated to the latest available version that addresses this vulnerability.

3

Who can exploit CVE-2026-54404?

CVE-2026-54404 can be exploited by a malicious actor with low privileges who has access to the network.

4

What type of vulnerability is CVE-2026-54404?

CVE-2026-54404 involves authenticated SQL Injection vulnerabilities within UniFi OS.

5

What impact does CVE-2026-54404 have on UniFi OS devices?

CVE-2026-54404 allows potential privilege escalation on compromised UniFi OS devices or instances.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203