CVE-2026-47369: Ubiquiti Inc Efg
Critical severity, CVSS 9.9. EPSS: 0.5% chance of exploitation in the next 30 days.
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.
Affected products
- Ubiquiti Inc Efg: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Envr: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Envr-Core: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Express: before 4.0.15 (fixed in 4.0.15)
- Ubiquiti Inc Express 7: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Ucg-Fiber: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Ucg-Industrial: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Ucg-Max: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Ucg-Ultra: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Uck: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Uck-Enterprise: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Uckp: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udm: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udm-Beast: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udm-Pro: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udm-Pro-Max: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udm-SE: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udr: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udr-5g: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc UDR7: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udw: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Unas-2: before 5.1.16 (fixed in 5.1.16)
- Ubiquiti Inc Unas-4: before 5.1.16 (fixed in 5.1.16)
- Ubiquiti Inc Unas-Pro: before 5.1.16 (fixed in 5.1.16)
- Ubiquiti Inc Unas-Pro-4: before 5.1.16 (fixed in 5.1.16)
- and 7 more
Published 2026-06-12. Last modified 2026-06-17.