Description
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances.
Published: 2026-07-02
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Server‑Side Request Forgery (SSRF) that lets an attacker with limited network access send arbitrary internal requests from a UniFi OS device. This flaw, identified as CWE‑918, can enable the attacker to gain full administrative control of the affected device, compromising confidentiality, integrity, and availability of the network infrastructure.

Affected Systems

The flaw impacts all Ubiquiti Inc. UniFi OS-based products, including Cloud Gateways, Cloud Keys, Dream Machines, Dream Routers, Dream Wall, Enterprise Firewall Core, Enterprise Fortress Gateway, Enterprise Video Recorders, Express 7, Network Attached Storage, Network Video Recorders, and the UniFi OS Server. No specific firmware versions are listed, so any current installation is presumed vulnerable until a patched release is applied.

Risk and Exploitability

The CVSS score of 7.7 classifies the issue as high severity, but the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not documented in CISA’s KEV catalog, meaning no known active exploitation has been reported. Based on the description, the most likely attack vector involves a local network actor who already has low privileges using the SSRF capability to issue privileged internal requests; this inference is drawn from the stated requirement for network access and low privileges.

Generated by OpenCVE AI on July 22, 2026 at 13:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest firmware updates or patches from the Ubiquiti support site, following the guidance in the official advisory at https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc.
  • If a patch is not yet available, disable or restrict any services on the device that generate outbound HTTP requests to prevent the SSRF path from being exercised.
  • Segment the UniFi OS devices onto isolated VLANs or enforce strict firewall rules to limit their access to internal services, reducing the potential impact of a successful SSRF.

Generated by OpenCVE AI on July 22, 2026 at 13:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery Enabling Privilege Escalation on UniFi OS Devices

Fri, 17 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery Enabling Privilege Escalation on UniFi OS Devices

Wed, 15 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Server-Side Request Forgery in Ubiquiti UniFi OS Devices Enables Privilege Escalation

Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Server-Side Request Forgery in Ubiquiti UniFi OS Devices Enables Privilege Escalation

Mon, 13 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title SSRF Enables Privilege Escalation on Ubiquiti UniFi OS Devices

Sun, 12 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title SSRF Enables Privilege Escalation on Ubiquiti UniFi OS Devices

Sat, 11 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title SSRF Permits Privilege Escalation on Ubiquiti UniFi OS Devices

Fri, 10 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title SSRF Permits Privilege Escalation on Ubiquiti UniFi OS Devices

Wed, 08 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery Enables Privilege Escalation on Ubiquiti UniFi OS Devices

Wed, 08 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery Enables Privilege Escalation on Ubiquiti UniFi OS Devices

Tue, 07 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery Allowing Privilege Escalation in Ubiquiti UniFi OS Devices

Mon, 06 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery Allowing Privilege Escalation in Ubiquiti UniFi OS Devices

Mon, 06 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery Leading to Privilege Escalation in Ubiquiti UniFi OS

Sun, 05 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery Leading to Privilege Escalation in Ubiquiti UniFi OS

Sun, 05 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery in Ubiquiti UniFi OS Enables Privilege Escalation

Sun, 05 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery in Ubiquiti UniFi OS Enables Privilege Escalation

Sat, 04 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title SSRF Exploit Allows Privilege Escalation in UniFi OS Devices

Sat, 04 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title SSRF Exploit Allows Privilege Escalation in UniFi OS Devices

Sat, 04 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery Allows Local Privilege Escalation in UniFi OS Devices

Fri, 03 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery Allows Local Privilege Escalation in UniFi OS Devices

Fri, 03 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title SSRF Exploitation Enables Privilege Escalation on UniFi OS Devices

Thu, 02 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title SSRF Exploitation Enables Privilege Escalation on UniFi OS Devices

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances.
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-02T15:51:58.264Z

Reserved: 2026-06-13T15:00:00.604Z

Link: CVE-2026-54401

cve-icon Vulnrichment

Updated: 2026-07-02T15:48:50.443Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T13:30:05Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)