← Back to CVE List
Vulnerability Intelligence Report

CVE-2026-47368

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data from such UniFi OS devices or instances.

No Active Exploit Signals
CVSS Base Score
8.6
HIGH
Exploitability:3.9
Impact Score:4.0
EPSS Probability:0.36%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-22 ↗CWE-22 Path Traversal

Affected Products & Versions

Vendor Product Affected Versions
Ubiquiti Inc UniFi OS Server 0 < 5.1.15 (affected)
Ubiquiti Inc Express 0 < 4.0.15 (affected)
Ubiquiti Inc UDM 0 < 5.1.15 (affected)
Ubiquiti Inc UDM-Pro 0 < 5.1.15 (affected)
Ubiquiti Inc UDM-SE 0 < 5.1.15 (affected)
Ubiquiti Inc UDM-Pro-Max 0 < 5.1.15 (affected)
Ubiquiti Inc UDM-Beast 0 < 5.1.15 (affected)
Ubiquiti Inc EFG 0 < 5.1.15 (affected)
Ubiquiti Inc UDW 0 < 5.1.15 (affected)
Ubiquiti Inc UDR 0 < 5.1.15 (affected)
Ubiquiti Inc UDR7 0 < 5.1.15 (affected)
Ubiquiti Inc UDR-5G 0 < 5.1.15 (affected)
Ubiquiti Inc Express 7 0 < 5.1.15 (affected)
Ubiquiti Inc UNVR 0 < 5.1.15 (affected)
Ubiquiti Inc UNVR-Pro 0 < 5.1.15 (affected)
Ubiquiti Inc UNVR-Instant 0 < 5.1.15 (affected)
Ubiquiti Inc UNVR-G2 0 < 5.1.15 (affected)
Ubiquiti Inc UNVR-G2-Pro 0 < 5.1.15 (affected)
Ubiquiti Inc ENVR 0 < 5.1.15 (affected)
Ubiquiti Inc ENVR-Core 0 < 5.1.15 (affected)
Ubiquiti Inc UNAS-2 0 < 5.1.16 (affected)
Ubiquiti Inc UNAS-4 0 < 5.1.16 (affected)
Ubiquiti Inc UNAS-Pro 0 < 5.1.16 (affected)
Ubiquiti Inc UNAS-Pro-4 0 < 5.1.16 (affected)
Ubiquiti Inc UNAS-Pro-8 0 < 5.1.16 (affected)
Ubiquiti Inc UCKP 0 < 5.1.15 (affected)
Ubiquiti Inc UCK 0 < 5.1.15 (affected)
Ubiquiti Inc UCK-Enterprise 0 < 5.1.15 (affected)
Ubiquiti Inc UCG-Ultra 0 < 5.1.15 (affected)
Ubiquiti Inc UCG-Max 0 < 5.1.15 (affected)
Ubiquiti Inc UCG-Fiber 0 < 5.1.15 (affected)
Ubiquiti Inc UCG-Industrial 0 < 5.1.15 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.355%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityHackerOne · Bug Bounty Provider · USA
Reserved2026-05-19T15:00:09
Published2026-06-12T02:27:43
Last Updated2026-06-12T14:30:10

LINK COPIED TO CLIPBOARD