Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 63.9%; technical severity is CVSS 10.0.
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.
Who should care
- Teams operating UniFi OS, Enterprise Fortress Gateway Firmware, Enterprise Network Video Recorder Core Firmware +30 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether UniFi OS, Enterprise Fortress Gateway Firmware, Enterprise Network Video Recorder Core Firmware +30 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Patch
Technical details
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- CWE
- CWE-22
- Affected versions
- Ubiquiti UniFi OS; Ui Enterprise Fortress Gateway Firmware (End Excluding 5.1.12); Ui Enterprise Network Video Recorder Core Firmware (End Excluding 5.1.12); Ui Enterprise Network Video Recorder Firmware (End Excluding 5.1.12); Ui Unas 2 Firmware (End Excluding 5.1.10); Ui Unas 4 Firmware (End Excluding 5.1.10); Ui Unas Pro 4 Firmware (End Excluding 5.1.10); Ui Unas Pro 8 Firmware (End Excluding 5.1.10)
- Fixed versions
- Ui Enterprise Fortress Gateway Firmware (Fixed from 5.1.12); Ui Enterprise Network Video Recorder Core Firmware (Fixed from 5.1.12); Ui Enterprise Network Video Recorder Firmware (Fixed from 5.1.12); Ui Unas 2 Firmware (Fixed from 5.1.10); Ui Unas 4 Firmware (Fixed from 5.1.10); Ui Unas Pro 4 Firmware (Fixed from 5.1.10); Ui Unas Pro 8 Firmware (Fixed from 5.1.10); Ui Unas Pro Firmware (Fixed from 5.1.10)
- Published
- 22 May 2026
- Attack vector
- Network
- Privileges required
- None
- User interaction
- None
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 63.9%
- Signal calculated at 81