top of page
perceptive_background_267k.jpg

A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate priv…

Published:

1 juli 2026 om 22:00:00

Alert date:

2 juli 2026 om 17:05:12

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Mobile & IoT, Identity & Access

CVE-2026-55115 is a Server-Side Request Forgery (SSRF) vulnerability identified in the UniFi Protect Application. A malicious actor with low privileges and network access can exploit this flaw to escalate privileges on the host device. The vulnerability poses a significant risk as it allows privilege escalation from a relatively low access level. Ubiquiti has published a security advisory bulletin addressing this issue. The NVD entry is currently awaiting full analysis. Organizations running UniFi Protect should apply patches or mitigations as soon as they become available. The vulnerability is rated as high criticality given the potential for privilege escalation.

Technical details

Mitigation steps:

Affected products:

UniFi Protect Application

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page