Ubiquiti UniFi Network Application
Our sources currently list 9 known vulnerabilities affecting Ubiquiti UniFi Network Application. 1 is rated critical severity.
Last updated: 22 July 2026, 20:37 AEST
No current ASD advisory names this product.That describes the Australian Signals Directorate’s publication record — it is not a statement that this product is free of vulnerabilities. See the list below.
| CVE | Severity | Exploitation | Published | Summary |
|---|---|---|---|---|
| CVE-2024-42025 | High (7.8) | No exploitation reported | A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.3.32 and earlier) allows a malicious actor with uni… | |
| CVE-2023-28365 | Critical (9.1) | No exploitation reported | A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems allows application administrators to execute malicious comma… | |
| CVE-2023-41721 | Medium (5.3) | No exploitation reported | Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access contr… | |
| CVE-2026-54406 | High (8.7) | No exploitation reported | A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi Network Application to escalat… | |
| CVE-2023-32000 | Medium (4.8) | No exploitation reported | A Cross-Site Scripting (XSS) vulnerability found in UniFi Network (Version 7.3.83 and earlier) allows a malicious actor with Site Administrator credentials to escalate privileges b… | |
| CVE-2026-54405 | High (7.5) | No exploitation reported | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Denial of Service (DoS) attack… | |
| CVE-2026-55114 | High (8.8) | No exploitation reported | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges wit… | |
| CVE-2026-56842 | High (7.5) | No exploitation reported | A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Network Application to persist privi… | |
| CVE-2026-55118 | High (8.3) | No exploitation reported | A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application t… |
Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.
Let's talk
Running Ubiquiti UniFi Network Application?
Our Newcastle team can audit your Ubiquiti estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.
