CVE-2026-47369

9.9CRITICAL

Key Information:

Vendor
CVE Published:
12 June 2026

What is CVE-2026-47369?

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.

Affected Version(s)

EFG 0 < 5.1.15

ENVR 0 < 5.1.15

ENVR-Core 0 < 5.1.15

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.