Vulnerability Description
A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to escalate privileges within such UniFi OS devices or instances.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ui | Unifi Dream Machine Beast Firmware | <= 5.1.15 |
| Ui | Unifi Dream Machine Beast | - |
| Ui | Enterprise Fortress Gateway Firmware | <= 5.1.15 |
| Ui | Enterprise Fortress Gateway | - |
| Ui | Unifi Dream Router Firmware | <= 5.1.15 |
| Ui | Unifi Dream Router | - |
| Ui | Unifi Dream Wall Firmware | <= 5.1.15 |
| Ui | Unifi Dream Wall | - |
| Ui | Unifi Dream Router 7 Firmware | <= 5.1.15 |
| Ui | Unifi Dream Router 7 | - |
| Ui | Unifi Express 7 Firmware | <= 5.1.15 |
| Ui | Unifi Express 7 | - |
| Ui | Unifi Cloudkey Firmware | <= 5.1.15 |
| Ui | Unifi Cloudkey | - |
| Ui | Unifi Cloud Key Plus Firmware | <= 5.1.15 |
| Ui | Unifi Cloud Key Plus | - |
| Ui | Unifi Cloudkey Enterprise Firmware | <= 5.1.15 |
| Ui | Unifi Cloudkey Enterprise | - |
| Ui | Unifi Network Video Recorder Firmware | <= 5.1.15 |
| Ui | Unifi Network Video Recorder | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-54404?
CVE-2026-54404 is a vulnerability with a CVSS score of 8.8 (HIGH). A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to escalate privileges within such UniFi OS devi...
How severe is CVE-2026-54404?
CVE-2026-54404 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-54404?
Check the references section above for vendor advisories and patch information. Affected products include: Ui Unifi Dream Machine Beast Firmware, Ui Unifi Dream Machine Beast, Ui Enterprise Fortress Gateway Firmware, Ui Enterprise Fortress Gateway, Ui Unifi Dream Router Firmware.