


Perceptive Security
SOC/SIEM Consultancy

A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate priv…
Published:
1 juli 2026 om 22:00:00
Alert date:
2 juli 2026 om 17:05:12
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT, Identity & Access
CVE-2026-55115 is a Server-Side Request Forgery (SSRF) vulnerability identified in the UniFi Protect Application. A malicious actor with low privileges and network access can exploit this flaw to escalate privileges on the host device. The vulnerability poses a significant risk as it allows privilege escalation from a relatively low access level. Ubiquiti has published a security advisory bulletin addressing this issue. The NVD entry is currently awaiting full analysis. Organizations running UniFi Protect should apply patches or mitigations as soon as they become available. The vulnerability is rated as high criticality given the potential for privilege escalation.
Technical details
Mitigation steps:
Affected products:
UniFi Protect Application
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-55115
https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
