VDB
GCVE-110-NCSC-2026-221
GCVE-110-NCSC-2026-221
Advisory PublishedCVSS 10.0/10
A Path Traversal vulnerability in certain UniFi OS devices enables a malicious actor with network access to bypass authentication mechanisms, potentially compromising device security.
Weaknesses (CWE)
CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-918Server-Side Request Forgery (SSRF)CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-942Permissive Cross-domain Security Policy with Untrusted DomainsCWE-863Incorrect Authorization
Risk Scores
CVSS 3.1
10.0/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Ubiquiti Inc | vers:unknown/* | — | — |
Aliases
CVE-2026-50746CVE-2026-50747CVE-2026-50748CVE-2026-54400CVE-2026-54401CVE-2026-54402CVE-2026-54403CVE-2026-54404CVE-2026-54405CVE-2026-54406CVE-2026-54407CVE-2026-54408CVE-2026-54409CVE-2026-55110CVE-2026-55111CVE-2026-55112CVE-2026-55113CVE-2026-55114CVE-2026-55115CVE-2026-55116CVE-2026-55117CVE-2026-55118CVE-2026-55119CVE-2026-56841CVE-2026-56842
Browse GCVE Records
73,873 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.