← Back to CVE List
Vulnerability Intelligence Report

CVE-2026-47370

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Command Injection within such UniFi OS devices or instances.

No Active Exploit Signals
CVSS Base Score
9.9
CRITICAL
Exploitability:3.2
Impact Score:6.1
EPSS Probability:0.83%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-20 ↗CWE-20 Improper Input Validation

Affected Products & Versions

Vendor Product Affected Versions
Ubiquiti Inc UniFi OS Server 0 < 5.1.15 (affected)
Ubiquiti Inc Express 0 < 4.0.15 (affected)
Ubiquiti Inc UDM 0 < 5.1.15 (affected)
Ubiquiti Inc UDM-Pro 0 < 5.1.15 (affected)
Ubiquiti Inc UDM-SE 0 < 5.1.15 (affected)
Ubiquiti Inc UDM-Pro-Max 0 < 5.1.15 (affected)
Ubiquiti Inc UDM-Beast 0 < 5.1.15 (affected)
Ubiquiti Inc EFG 0 < 5.1.15 (affected)
Ubiquiti Inc UDW 0 < 5.1.15 (affected)
Ubiquiti Inc UDR 0 < 5.1.15 (affected)
Ubiquiti Inc UDR7 0 < 5.1.15 (affected)
Ubiquiti Inc UDR-5G 0 < 5.1.15 (affected)
Ubiquiti Inc Express 7 0 < 5.1.15 (affected)
Ubiquiti Inc UNVR 0 < 5.1.15 (affected)
Ubiquiti Inc UNVR-Pro 0 < 5.1.15 (affected)
Ubiquiti Inc UNVR-Instant 0 < 5.1.15 (affected)
Ubiquiti Inc UNVR-G2 0 < 5.1.15 (affected)
Ubiquiti Inc UNVR-G2-Pro 0 < 5.1.15 (affected)
Ubiquiti Inc ENVR 0 < 5.1.15 (affected)
Ubiquiti Inc ENVR-Core 0 < 5.1.15 (affected)
Ubiquiti Inc UNAS-2 0 < 5.1.16 (affected)
Ubiquiti Inc UNAS-4 0 < 5.1.16 (affected)
Ubiquiti Inc UNAS-Pro 0 < 5.1.16 (affected)
Ubiquiti Inc UNAS-Pro-4 0 < 5.1.16 (affected)
Ubiquiti Inc UNAS-Pro-8 0 < 5.1.16 (affected)
Ubiquiti Inc UCKP 0 < 5.1.15 (affected)
Ubiquiti Inc UCK 0 < 5.1.15 (affected)
Ubiquiti Inc UCK-Enterprise 0 < 5.1.15 (affected)
Ubiquiti Inc UCG-Ultra 0 < 5.1.15 (affected)
Ubiquiti Inc UCG-Max 0 < 5.1.15 (affected)
Ubiquiti Inc UCG-Fiber 0 < 5.1.15 (affected)
Ubiquiti Inc UCG-Industrial 0 < 5.1.15 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.834%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityHackerOne · Bug Bounty Provider · USA
Reserved2026-05-19T15:00:09
Published2026-06-12T02:27:43
Last Updated2026-06-13T03:55:51

LINK COPIED TO CLIPBOARD