Summary
CVE-2026-48610 is an Improper Access Control vulnerability affecting a wide range of devices running Ubiquiti UniFi OS. Under certain network configurations, an unauthenticated, network-accessible attacker can exploit the flaw to make unauthorized changes to affected UniFi OS devices. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) and was disclosed as part of Ubiquiti Security Advisory Bulletin 064.
Technical details
- Root cause: Improper access control within the UniFi OS management layer, allowing unauthorized requests to bypass access restrictions.
- Trigger conditions: Exploitable under certain network configurations; attackers require network-level access to the targeted device.
- Attack vector: Network-reachable with no authentication (
PR:N) and no user interaction (UI:N) required. Attack complexity is rated High (AC:H), reflecting the requirement for a specific network configuration to be present. - Impact: Successful exploitation allows a remote attacker to make unauthorized changes to the underlying UniFi OS device. The CVSS impact ratings are High across Confidentiality, Integrity, and Availability (
C:H/I:H/A:H).
Affected software
- UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UCG-Ultra, UCG-Max, UCG-Industrial, UCG-Fiber — UniFi OS version 5.1.12 and earlier
- UDM-Beast — UniFi OS version 5.1.11 and earlier
Severity
- CVSS v3.1 Base Score: 8.1 (High)
- Vector String:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate action — apply the vendor patch: Update all affected UniFi OS devices to version 5.1.15 or later, as released by Ubiquiti in Security Advisory Bulletin 064.
- Network mitigation: Where immediate patching is not feasible, restrict management interface access to trusted internal networks and block direct exposure of the UniFi OS management interface to untrusted networks.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

