Description
A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.
Published: 2026-08-26
Score: 9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An Active Debug Code flaw in UniFi OS allows an attacker with network access and low privileges to elevate their rights on affected devices or instances. The vulnerability can be triggered under certain conditions, enabling the attacker to gain full control of configuration, network traffic, and potentially deploy further compromise tools. The flaw is a classic example of improper handling of debug services, which is cataloged as CWE-489.

Affected Systems

Affected devices include Ubiquiti Cloud Gateways, Cloud Keys, Dream Machines, Dream Routers, Dream Wall, Enterprise Firewall Core, Enterprise Fortress Gateway, Enterprise Network Attached Storage, Enterprise Network Video Recorders, Express 7, Network Attached Storage, Network Video Recorders, and the UniFi OS Server. Specific version information was not disclosed in the advisory.

Risk and Exploitability

The CVSS score of 9 indicates a critical severity, and the EPSS score is not available, suggesting limited public exploitation data at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local network scenario where an actor with low privileges can manipulate debug code, thus raising their privileges within the device.

Generated by OpenCVE AI on August 26, 2026 at 11:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and apply any firmware updates that contain a fix for the Active Debug Code vulnerability.
  • Disable active debug mode or any exposed debugging services on the UniFi OS device through the configuration portal or command line.
  • Apply network segmentation or firewall rules to restrict unauthenticated or low‑privilege users from accessing the device’s debug interfaces.
  • Monitor system logs for unexpected debug activity or privilege escalation events and investigate anomalies promptly.

Generated by OpenCVE AI on August 26, 2026 at 11:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Title Active Debug Code Vulnerability Allows Privilege Escalation in UniFi OS Devices

Wed, 26 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.
Weaknesses CWE-489
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Ubiquiti

Published:

Updated: 2026-08-26T13:20:12.910Z

Reserved: 2026-08-20T20:32:37.793Z

Link: CVE-2026-77545

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T12:00:05Z

Weaknesses