Description
A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (CORS) misconfiguration found in UniFi OS to trigger actions in UniFi OS using that user's session.
Published: 2026-07-02
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A malicious actor can lure an authenticated user to a malicious web page. The Cross‑Origin Resource Sharing policy in UniFi OS is overly permissive, causing the browser to automatically forward the victim’s authentication tokens with cross‑origin requests. This allows the attacker to invoke privileged API calls that the logged‑in user could normally perform, enabling unauthorized modifications, data exfiltration, or other privileged actions without compromising credentials.

Affected Systems

The flaw affects devices running UniFi OS, which includes Ubiquiti Inc products such as Cloud Gateways, Cloud Keys, Dream Machines, Dream Routers, Dream Wall, Enterprise Firewall Core, Enterprise Fortress Gateway, Enterprise Video Recorders, Express 7, Network Attached Storage, Network Video Recorders and the UniFi OS Server. Affected version information is not specified, so administrators should verify whether their firmware or software includes the CORS fix.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, while the EPSS score of <1% suggests a low probability of real‑world exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is social engineering: a victim, while logged in to UniFi OS, visits a malicious site that triggers cross‑origin requests under the target’s session. No local privilege escalation is required; the attack depends on an authenticated user’s presence in a browser context.

Generated by OpenCVE AI on July 22, 2026 at 13:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update that corrects the CORS policy misconfiguration for all UniFi OS devices.
  • If a patch is not yet available, configure the UniFi OS CORS settings to allow only trusted origins and remove any wildcard or broad Origin headers.
  • Enable two‑factor authentication on all UniFi OS accounts and conduct user education to mitigate phishing attempts.

Generated by OpenCVE AI on July 22, 2026 at 13:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title CORS Misconfiguration in UniFi OS Enables Unauthorized Actions via Authenticated Sessions

Fri, 17 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title CORS Misconfiguration in UniFi OS Enables Unauthorized Actions via Authenticated Sessions

Wed, 15 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title CORS Misconfiguration in UniFi OS Enables Unauthorized Actions

Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title CORS Misconfiguration in UniFi OS Enables Unauthorized Actions

Mon, 13 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title CORS misconfiguration in UniFi OS permits attackers to execute privileged actions using a victim's session

Sat, 11 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title CORS misconfiguration in UniFi OS permits attackers to execute privileged actions using a victim's session

Fri, 10 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title CORS Misconfiguration in UniFi OS Enables Unauthorized API Calls

Thu, 09 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title CORS Misconfiguration in UniFi OS Enables Unauthorized API Calls

Thu, 09 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title CORS Misconfiguration Enables Unauthorized Actions in UniFi OS

Wed, 08 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title CORS Misconfiguration Enables Unauthorized Actions in UniFi OS

Mon, 06 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title CORS Misconfiguration in UniFi OS Enabling Unauthorized Actions via Authenticated User Session

Mon, 06 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title CORS Misconfiguration in UniFi OS Enabling Unauthorized Actions via Authenticated User Session

Sun, 05 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title CORS Misconfiguration Exploitable by Authenticated Users in UniFi OS

Sun, 05 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title CORS Misconfiguration Exploitable by Authenticated Users in UniFi OS

Sun, 05 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title UniFi OS CORS Misconfiguration Allows Unauthorized Actions in Authenticated Sessions

Sat, 04 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title UniFi OS CORS Misconfiguration Allows Unauthorized Actions in Authenticated Sessions

Sat, 04 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title CORS Misconfiguration in UniFi OS Enabling Unauthorized Actions

Fri, 03 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title CORS Misconfiguration in UniFi OS Enabling Unauthorized Actions

Fri, 03 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title CORS Misconfiguration Enables Authenticated Session Abuse in UniFi OS

Thu, 02 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title CORS Misconfiguration Enables Authenticated Session Abuse in UniFi OS

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (CORS) misconfiguration found in UniFi OS to trigger actions in UniFi OS using that user's session.
Weaknesses CWE-942
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-02T15:52:20.711Z

Reserved: 2026-06-16T15:00:01.614Z

Link: CVE-2026-55110

cve-icon Vulnrichment

Updated: 2026-07-02T15:41:36.930Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T13:30:05Z

Weaknesses
  • CWE-942

    Permissive Cross-domain Security Policy with Untrusted Domains