Description
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances.
Published: 2026-07-02
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Server‑Side Request Forgery that allows an attacker who has only limited network access and low privileges to send arbitrary internal requests from a UniFi OS device. The flaw, known as CWE‑918, can cause the attacker to gain administrative control over the device, thereby compromising the confidentiality, integrity, and availability of the network infrastructure.

Affected Systems

All Ubiquiti Inc. Uni Recorders, Express‑7, Network Attached Storage, Network Video Recorders, and the UniFi OS Server—is vulnerable. No specific firmware versions are listed, so any current installation is presumed at risk until a patch is applied.

Risk and Exploitability

The CVSS score of 7.7 classifies the issue as high severity. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not included in the CISA KEV catalog, meaning no publicly documented exploitation is known. Based on the requirement for network and low‑privilege access, the most likely attack vector involves a local network actor leveraging the SSRF path to issue privileged internal requests from the device.

Generated by OpenCVE AI on August 1, 2026 at 21:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest firmware updates or patches from Ubiquiti’s support site, following the guidance in the official advisory at https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc or restrict any services on the device that generate outbound HTTP requests to eliminate the SSRF pathway.
  • Segment the UniFi OS devices onto isolated VLANs or enforce strict firewall rules to limit their access to internal services, thereby reducing the potential impact of a successful SSRF.
  • Configure audit logging on UniFi OS devices to capture outbound request activity and monitor for abnormal SSRF patterns.

Generated by OpenCVE AI on August 1, 2026 at 21:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery Enables Privilege Escalation on Ubiquiti UniFi OS Devices

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Server‑Side Request Forgery in Ubiquiti UniFi OS Devices

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Server‑Side Request Forgery in Ubiquiti UniFi OS Devices

Wed, 22 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery Enabling Privilege Escalation on UniFi OS Devices

Fri, 17 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery Enabling Privilege Escalation on UniFi OS Devices

Wed, 15 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Server-Side Request Forgery in Ubiquiti UniFi OS Devices Enables Privilege Escalation

Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Server-Side Request Forgery in Ubiquiti UniFi OS Devices Enables Privilege Escalation

Mon, 13 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title SSRF Enables Privilege Escalation on Ubiquiti UniFi OS Devices

Sun, 12 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title SSRF Enables Privilege Escalation on Ubiquiti UniFi OS Devices

Sat, 11 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title SSRF Permits Privilege Escalation on Ubiquiti UniFi OS Devices

Fri, 10 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title SSRF Permits Privilege Escalation on Ubiquiti UniFi OS Devices

Wed, 08 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery Enables Privilege Escalation on Ubiquiti UniFi OS Devices

Wed, 08 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery Enables Privilege Escalation on Ubiquiti UniFi OS Devices

Tue, 07 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery Allowing Privilege Escalation in Ubiquiti UniFi OS Devices

Mon, 06 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery Allowing Privilege Escalation in Ubiquiti UniFi OS Devices

Mon, 06 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery Leading to Privilege Escalation in Ubiquiti UniFi OS

Sun, 05 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery Leading to Privilege Escalation in Ubiquiti UniFi OS

Sun, 05 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery in Ubiquiti UniFi OS Enables Privilege Escalation

Sun, 05 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery in Ubiquiti UniFi OS Enables Privilege Escalation

Sat, 04 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title SSRF Exploit Allows Privilege Escalation in UniFi OS Devices

Sat, 04 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title SSRF Exploit Allows Privilege Escalation in UniFi OS Devices

Sat, 04 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery Allows Local Privilege Escalation in UniFi OS Devices

Fri, 03 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery Allows Local Privilege Escalation in UniFi OS Devices

Fri, 03 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title SSRF Exploitation Enables Privilege Escalation on UniFi OS Devices

Thu, 02 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title SSRF Exploitation Enables Privilege Escalation on UniFi OS Devices

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances.
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Ui Enterprise Firewall Core Enterprise Firewall Core Firmware Enterprise Fortress Gateway Enterprise Fortress Gateway Firmware Enterprise Network Video Recorder Enterprise Network Video Recorder Core Enterprise Network Video Recorder Core Firmware Enterprise Network Video Recorder Firmware Unas 2 Unas 2 Firmware Unas 4 Unas 4 Firmware Unas Pro Unas Pro 4 Unas Pro 4 Firmware Unas Pro 8 Unas Pro 8 Firmware Unas Pro Firmware Unifi Cloud Gateway Fiber Unifi Cloud Gateway Fiber Firmware Unifi Cloud Gateway Industrial Unifi Cloud Gateway Industrial Firmware Unifi Cloud Gateway Max Unifi Cloud Gateway Max Firmware Unifi Cloud Gateway Ultra Unifi Cloud Gateway Ultra Firmware Unifi Cloud Key Plus Unifi Cloud Key Plus Firmware Unifi Cloudkey Unifi Cloudkey Enterprise Unifi Cloudkey Enterprise Firmware Unifi Cloudkey Firmware Unifi Dream Machine Unifi Dream Machine Beast Unifi Dream Machine Beast Firmware Unifi Dream Machine Firmware Unifi Dream Machine Pro Unifi Dream Machine Pro Firmware Unifi Dream Machine Pro Max Unifi Dream Machine Pro Max Firmware Unifi Dream Machine Special Edition Unifi Dream Machine Special Edition Firmware Unifi Dream Router Unifi Dream Router 5g Max Unifi Dream Router 5g Max Firmware Unifi Dream Router 7 Unifi Dream Router 7 Firmware Unifi Dream Router Firmware Unifi Dream Wall Unifi Dream Wall Firmware Unifi Express 7 Unifi Express 7 Firmware Unifi Network Video Recorder Unifi Network Video Recorder Firmware Unifi Network Video Recorder G2 Unifi Network Video Recorder G2 Firmware Unifi Network Video Recorder G2 Pro Unifi Network Video Recorder G2 Pro Firmware Unifi Network Video Recorder Instant Unifi Network Video Recorder Instant Firmware Unifi Network Video Recorder Pro Unifi Network Video Recorder Pro Firmware Unifi Os Server
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-02T15:51:58.264Z

Reserved: 2026-06-13T15:00:00.604Z

Link: CVE-2026-54401

cve-icon Vulnrichment

Updated: 2026-07-02T15:48:50.443Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-02T15:17:03.730

Modified: 2026-07-10T02:50:13.673

Link: CVE-2026-54401

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T21:30:06Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)