Description
A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges on the host device.
Published: 2026-07-02
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A malicious actor who can connect to the network and has low local privileges can exploit an improper access control flaw in UniFi OS Protect. The vulnerability (CWE‑284) allows the attacker to bypass authorization checks within the Protect application, elevating host privileges and potentially allowing the execution of privileged commands or further compromise of the device.

Affected Systems

The flaw impacts Ubiquiti Cloud Gateways, Cloud Keys, Dream Machines, Dream Routers, Dream Wall, Enterprise Video Recorders, and Network Video Recorders that run UniFi OS Protect; no specific version information is available, so current releases of these products are potentially affected.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% signals a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need network connectivity to the device and low initial privileges, then exploit the Protect application to gain elevated rights. Despite limited exploitation probability, the high gain justifies immediate mitigation.

Generated by OpenCVE AI on July 21, 2026 at 11:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware or software update from Ubiquiti for UniFi OS Protect
  • Restrict network access to the Protect application so only trusted devices can reach it
  • Enforce network segmentation to limit the attack surface
  • Enforce least‑privilege by reviewing and tightening user and role permissions within the Protect application

Generated by OpenCVE AI on July 21, 2026 at 11:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Ubiquiti UniFi OS Protect Allows Privilege Escalation

Fri, 17 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Ubiquiti UniFi OS Protect Allows Privilege Escalation

Thu, 16 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in Ubiquiti UniFi OS Protect

Tue, 14 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in Ubiquiti UniFi OS Protect

Mon, 13 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi OS Protect

Sun, 12 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi OS Protect

Sat, 11 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi OS Protect

Fri, 10 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi OS Protect

Thu, 09 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Protect

Thu, 09 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Protect

Wed, 08 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi OS Protect Allows Privilege Escalation

Tue, 07 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi OS Protect Allows Privilege Escalation

Mon, 06 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in UniFi OS Protect via Improper Access Control

Mon, 06 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in UniFi OS Protect via Improper Access Control

Sun, 05 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi OS Protect Allows Privilege Escalation on Ubiquiti Devices

Sun, 05 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi OS Protect Allows Privilege Escalation on Ubiquiti Devices

Sun, 05 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation Vulnerability in UniFi OS Protect

Sat, 04 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation Vulnerability in UniFi OS Protect

Sat, 04 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi OS Protect Application

Sat, 04 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi OS Protect Application

Fri, 03 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Protect Application

Thu, 02 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Protect Application

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges on the host device.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-02T15:51:35.516Z

Reserved: 2026-06-16T15:00:01.614Z

Link: CVE-2026-55112

cve-icon Vulnrichment

Updated: 2026-07-02T15:41:30.868Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:15:05Z

Weaknesses