CVE-2026-48610: Ubiquiti Inc Efg
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Under certain network configurations, a malicious actor with access to network could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.
Affected products
- Ubiquiti Inc Efg: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Express 7: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Ucg-Fiber: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Ucg-Industrial: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Ucg-Max: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Ucg-Ultra: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udm: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udm-Beast: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udm-Pro: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udm-Pro-Max: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udm-SE: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udr: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udr-5g: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc UDR7: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udw: before 5.1.15 (fixed in 5.1.15)
Published 2026-06-12. Last modified 2026-06-17.