Impact
The UniFi Protect Application contains an improper validation weakness that allows a Server‑Side Request Forgery (SSRF) flaw, classified as CWE‑918. The SSRF feature enables a malicious actor who can reach the device over the network and who holds a low‑privilege account in the application to send arbitrary HTTP requests to internal endpoints. By exploiting this path, the attacker can elevate privileges on the host device, transitioning from low‑privilege to higher‑privilege access and potentially modifying or sabotaging system configuration. This elevation can be achieved with no additional credentials once the SSRF path is triggered.
Affected Systems
The vulnerability affects Ubiquiti Inc’s UniFi Protect Application. Any instance that is reachable from the local network and exposes a low‑privilege user interface to management can be susceptible. Specific product versions are not listed in the advisory, so the risk applies to all current installations until a patch is applied.
Risk and Exploitability
The CVSS score of 9.9 classifies the flaw as critical, while the EPSS score of < 1% suggests that active exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a local network attacker or an attacker who has compromised a low‑privilege account. Once the SSRF path is engaged, privilege elevation occurs without further credentials, creating a high‑impact risk for any organization that relies on the Protect application.
OpenCVE Enrichment