Description
A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerability found in UniFi Protect Application to escalate privileges on the host device.
Published: 2026-07-02
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated SQL injection flaw within the UniFi Protect Application allows an attacker with low network privileges to inject arbitrary SQL commands. By manipulating query inputs, the attacker can bypass normal authorization checks and execute statements that elevate privileges on the host device, potentially giving full system control or enabling further exploitation.

Affected Systems

The vulnerability affects the UniFi Protect Application from Ubiquiti Inc. All versions released prior to the vendor’s fix are potentially vulnerable; the advisory does not specify a version range, so any deployment that has not yet applied the vendor’s update is at risk.

Risk and Exploitability

The CVSS score of 8.8 classifies the flaw as high severity. The EPSS score of less than 1% indicates exploitation probability is very low, but not zero, and the vulnerability is not listed in CISA KEV, meaning no confirmed active exploitation has been reported. Exploitation requires authenticated access over the local network; there is no known unauthenticated or remote attack surface.

Generated by OpenCVE AI on July 22, 2026 at 13:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch for UniFi Protect to update the database interface to use safe parameterized queries.
  • Restrict the management interface of the device to trusted, segmented networks or VLANs to limit exposure.
  • Enforce least privilege by removing administrative rights from user accounts that access the Protect application.
  • If a patch is not yet available, disable or block unused network services on the device to reduce the attack surface.

Generated by OpenCVE AI on July 22, 2026 at 13:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection in UniFi Protect Enables Local Privilege Escalation

Fri, 17 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection in UniFi Protect Enables Local Privilege Escalation

Wed, 15 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via SQL Injection in Ubiquiti UniFi Protect

Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via SQL Injection in Ubiquiti UniFi Protect

Sun, 12 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection in UniFi Protect Enables Local Privilege Escalation

Sat, 11 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection in UniFi Protect Enables Local Privilege Escalation

Fri, 10 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title SQL Injection in Ubiquiti UniFi Protect Enables Local Privilege Escalation

Thu, 09 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title SQL Injection in Ubiquiti UniFi Protect Enables Local Privilege Escalation

Thu, 09 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Authenticated SQL Injection in Ubiquiti UniFi Protect

Wed, 08 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Authenticated SQL Injection in Ubiquiti UniFi Protect

Tue, 07 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title SQL Injection in UniFi Protect Allows Local Privilege Escalation

Mon, 06 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title SQL Injection in UniFi Protect Allows Local Privilege Escalation

Mon, 06 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Authenticated SQL Injection in Ubiquiti UniFi Protect

Sun, 05 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Authenticated SQL Injection in Ubiquiti UniFi Protect

Sun, 05 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title SQL Injection in UniFi Protect Enables Local Privilege Escalation

Sun, 05 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title SQL Injection in UniFi Protect Enables Local Privilege Escalation

Sat, 04 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection allows local privilege escalation in Ubiquiti UniFi Protect

Sat, 04 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection allows local privilege escalation in Ubiquiti UniFi Protect

Sat, 04 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection Allows Local Privilege Escalation in UniFi Protect

Fri, 03 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection Allows Local Privilege Escalation in UniFi Protect

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerability found in UniFi Protect Application to escalate privileges on the host device.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-02T15:51:17.657Z

Reserved: 2026-06-23T15:00:03.631Z

Link: CVE-2026-56841

cve-icon Vulnrichment

Updated: 2026-07-02T15:41:26.659Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T13:30:05Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')