Description
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalate privileges on the device.
Published: 2026-08-26
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an attacker who can reach the UniFi Protect AI Key from the network to gain elevated privileges on the device, potentially enabling full control of configuration, data, and network traffic. The flaw is an Improper Access Control issue (CWE‑284) that can compromise the confidentiality, integrity, and availability of the device and any connected services.

Affected Systems

Ubiquiti Inc’s UniFi Protect AI Key product is affected. No specific version range is disclosed, so all currently deployed units should be considered at risk.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity, and while an EPSS score is not available, the attack would be straightforward for anyone with network access to the device. The issue is not listed in the CISA KEV catalog, but the high CVSS suggests a significant threat profile. The likely attack vector is network-based access to the device, exploiting the access control weakness to elevate privileges.

Generated by OpenCVE AI on August 26, 2026 at 12:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor-released patch for UniFi Protect AI Key
  • Implement firewall rules to restrict direct network access to the device to trusted management IPs only
  • Monitor device logs and network traffic for signs of unauthorized privileged activity
  • If a patch is not yet available, isolate the device from untrusted networks and enforce strict access control to mitigate exploitation.

Generated by OpenCVE AI on August 26, 2026 at 12:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Protect AI Key

Wed, 26 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalate privileges on the device.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Ubiquiti

Published:

Updated: 2026-08-26T12:38:19.953Z

Reserved: 2026-08-20T20:32:43.655Z

Link: CVE-2026-77557

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T12:30:05Z

Weaknesses