CVE-2026-54406
published 2026-07-02CVE-2026-54406: A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi Network…
PriorityP353high8.7CVSS 3.1
AVNACLPRHUINSCCNIHAH
EPSS
0.59%
45.9th percentile
A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi Network Application to escalate write permission on the host device.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ubiquiti_inc | unifi_network_application | < 10.4.57 | 10.4.57 |
| ui | unifi_network_application | < 10.4.57 | 10.4.57 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi Network Application to escalate write permission o
ghsa_unreviewed·2026-07-02
CVE-2026-54406 [HIGH] CWE-22 A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi Network Application to escalate write permission o
A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi Network Application to escalate write permission on the host device.
VulDB
Ubiquiti UniFi Network Application up to 10.4.56 path traversal
vuldb·2026-07-02·CVSS 8.7
CVE-2026-54406 [HIGH] Ubiquiti UniFi Network Application up to 10.4.56 path traversal
A vulnerability was found in Ubiquiti UniFi Network Application up to 10.4.56. It has been rated as critical. This affects an unknown part. This manipulation causes path traversal.
The identification of this vulnerability is CVE-2026-54406. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-02
Published