logo

Critical UniFi OS RCE Chain Grants Root Access Without Credentials

ID: bd631244-b766-53d2-aa75-d32010ca1aea

STIX ID: report--bd631244-b766-53d2-aa75-d32010ca1aea

Feed Name: GBHackers

Threat Score
95/100

Date Published: 2026-06-08

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

Security Advisory Bulletin 064 describes a critical chained vulnerability in UniFi OS Server (several CVEs) that allows an unauthenticated attacker to craft a single HTTP request to bypass the authentication gateway, exploit a command-injection sink in the package-update backend, and escalate to root (e.g., via sudo dpkg) to obtain persistent full control of the management plane; Bishop Fox reproduced the chain on 5.0.6 and fixes are provided in 5.0.8. Immediate mitigations include patching, blocking external admin access, and rotating all exposed secrets and keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.