VDB

GCVE-110-NCSC-2026-221

GCVE-110-NCSC-2026-221
Advisory PublishedCVSS 10.0/10
Vulnetix · Advisory published July 7, 2026
A Path Traversal vulnerability in certain UniFi OS devices enables a malicious actor with network access to bypass authentication mechanisms, potentially compromising device security.

Weaknesses (CWE)

CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-918Server-Side Request Forgery (SSRF)CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-942Permissive Cross-domain Security Policy with Untrusted DomainsCWE-863Incorrect Authorization

Risk Scores

CVSS 3.1
10.0/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
Ubiquiti Incvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

73,873 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›