CVE-2026-47368: Ubiquiti Inc Efg
High severity, CVSS 8.6. EPSS: 0.5% chance of exploitation in the next 30 days.
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data from such UniFi OS devices or instances.
Affected products
- Ubiquiti Inc Efg: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Envr: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Envr-Core: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Express: before 4.0.15 (fixed in 4.0.15)
- Ubiquiti Inc Express 7: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Ucg-Fiber: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Ucg-Industrial: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Ucg-Max: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Ucg-Ultra: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Uck: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Uck-Enterprise: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Uckp: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udm: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udm-Beast: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udm-Pro: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udm-Pro-Max: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udm-SE: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udr: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udr-5g: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc UDR7: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udw: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Unas-2: before 5.1.16 (fixed in 5.1.16)
- Ubiquiti Inc Unas-4: before 5.1.16 (fixed in 5.1.16)
- Ubiquiti Inc Unas-Pro: before 5.1.16 (fixed in 5.1.16)
- Ubiquiti Inc Unas-Pro-4: before 5.1.16 (fixed in 5.1.16)
- and 7 more
Published 2026-06-12. Last modified 2026-06-17.