CVE-2026-47368: A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data from such UniFi OS devices or instances
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data from such UniFi OS devices or instances.
Metrics
- CVSS v3.1
- 8.6
- Severity
- HIGH
- Fixed in
- 4.0.15
- Affected Products
- 32
HarborGuard Analysis
Synopsis
A path traversal vulnerability affects multiple Ubiquiti UniFi OS devices and instances, including the UniFi OS Server, Express, UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, and EFG. The flaw is reachable over the network without any authentication, and the scope impact extends beyond the vulnerable component itself. Successful exploitation allows an attacker to read arbitrary files from the affected device or instance, disclosing sensitive data. Patched-image rebuilds at versions 4.0.15, 5.1.15, and 5.1.16 are available on HarborGuard for environments running affected versions.
HarborGuard Coverage
Detection of CVE-2026-47368 is available across every HarborGuard environment, with the CVE matched against customer images within minutes of ingestion from upstream advisory feeds, including custom-built images that bundle UniFi OS components. Coverage extends to all registry types and CI pipeline stages where HarborGuard scanning is configured.
AvailableHarborGuard is capable of scoring this CVE at CVSS 8.6 (HIGH) and weighting it against each environment's compliance policy to determine urgency. Triage routing to the appropriate team or inbox within each customer organization is available as part of the standard pipeline workflow.
AvailableA patched-image rebuild at the applicable fix versions (4.0.15, 5.1.15, or 5.1.16 depending on the affected product line) becomes available through HarborGuard once the upstream fix is confirmed. For customers who opt into auto-remediation, HarborGuard is capable of performing the rebuild, running a regression test suite, and opening a PR against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker must reach the affected UniFi OS service over the network; no local or physical access is needed.
- AuthenticationNot required
No credentials or account of any kind are required to send the malicious request.
- Victim interactionNot required
Exploitation is entirely attacker-driven and requires no action from a user or administrator on the target device.
- Attack complexityDetail
The exploit is reliable and condition-free, requiring no race conditions or special environmental setup beyond network access.
Blast Radius
- An attacker reads arbitrary files from the affected UniFi OS device or instance, including configuration files, credentials, and internal state data.
- Because the CVSS scope is Changed, disclosed data may originate from components or services beyond the directly vulnerable UniFi OS process itself.
- Stolen credentials or API keys extracted from device files can be leveraged to pivot into other systems on the same network.
- Confidentiality impact is rated High; integrity and availability of the device are not directly affected by this vulnerability alone.
How HarborGuard Handles This
Available on HarborGuard: scanning for CVE-2026-47368 is active across all configured registries and pipelines, with matches surfaced within minutes of publication. For environments running affected UniFi OS versions below 4.0.15 or 5.1.15, a patched-image rebuild at the appropriate fix version is available. Where compliance policy permits auto-remediation, HarborGuard can execute the full remediation flow, rebuild, regression run, and PR opened against affected workloads, with a median time from CVE publication to merged patch PR of around 90 minutes for HIGH-severity issues in qualifying environments. Until a rebuild is deployed, compensating controls to consider include restricting network-policy ingress to UniFi OS management interfaces, applying egress filtering to limit lateral movement from compromised devices, and auditing stored credentials and API tokens that may reside on affected devices.
Fix available
- Ubiquiti Inc / UniFi OS Server< 5.1.15 (from 0)
- Ubiquiti Inc / Express< 4.0.15 (from 0)
- Ubiquiti Inc / UDM< 5.1.15 (from 0)
- Ubiquiti Inc / UDM-Pro< 5.1.15 (from 0)
- Ubiquiti Inc / UDM-SE< 5.1.15 (from 0)
- Ubiquiti Inc / UDM-Pro-Max< 5.1.15 (from 0)
- Ubiquiti Inc / UDM-Beast< 5.1.15 (from 0)
- Ubiquiti Inc / EFG< 5.1.15 (from 0)
- Ubiquiti Inc / UDW< 5.1.15 (from 0)
- Ubiquiti Inc / UDR< 5.1.15 (from 0)
- Ubiquiti Inc / UDR7< 5.1.15 (from 0)
- Ubiquiti Inc / UDR-5G< 5.1.15 (from 0)
- Ubiquiti Inc / Express 7< 5.1.15 (from 0)
- Ubiquiti Inc / UNVR< 5.1.15 (from 0)
- Ubiquiti Inc / UNVR-Pro< 5.1.15 (from 0)
- Ubiquiti Inc / UNVR-Instant< 5.1.15 (from 0)
- Ubiquiti Inc / UNVR-G2< 5.1.15 (from 0)
- Ubiquiti Inc / UNVR-G2-Pro< 5.1.15 (from 0)
- Ubiquiti Inc / ENVR< 5.1.15 (from 0)
- Ubiquiti Inc / ENVR-Core< 5.1.15 (from 0)
- Ubiquiti Inc / UNAS-2< 5.1.16 (from 0)
- Ubiquiti Inc / UNAS-4< 5.1.16 (from 0)
- Ubiquiti Inc / UNAS-Pro< 5.1.16 (from 0)
- Ubiquiti Inc / UNAS-Pro-4< 5.1.16 (from 0)
- Ubiquiti Inc / UNAS-Pro-8< 5.1.16 (from 0)
- Ubiquiti Inc / UCKP< 5.1.15 (from 0)
- Ubiquiti Inc / UCK< 5.1.15 (from 0)
- Ubiquiti Inc / UCK-Enterprise< 5.1.15 (from 0)
- Ubiquiti Inc / UCG-Ultra< 5.1.15 (from 0)
- Ubiquiti Inc / UCG-Max< 5.1.15 (from 0)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N