CVE-2026-55115Disclosure(ui / unifi_protect)

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ui unifi_protect systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • unifi_protect

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-07-02); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
unifi_protect

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-07-02: 3Mentions · 2026-07-03: 1Mentions · 2026-08-03: 1Patch / Workaround · 2026-07-03: 1Technical Details · 2026-07-02: 3Technical Details · 2026-07-03: 1Technical Details · 2026-08-03: 107-0207-0308-03
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-023
Disclosure3
2026-07-031
Patch1
2026-08-031
General1
Full discourse5 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Ubiquiti UniFi Protect Application SSRF to Privilege Escalation (CVE-2026-55115) A Server-Side Request Forgery flaw in Ubiquiti's UniFi Protect Application lets a network-adjacent attacker with low privileges coerce the application into making attacker-controlled server-side requests. This can be abused to reach internal endpoints and services and to escalate privileges on the underlying host device. Because UniFi Protect runs the camera/NVR surveillance stack, host-level privilege escalation undermines both the appliance and the video infrastructure it manages. The flaw is remotely exploitable with low complexity, needs only a low-privileged account, and requires no user interaction (CVSS 9.9). 👉Upgrade to UniFi Protect Application 7.1.83.

    Post summary

    The post announces a critical SSRF‑to‑privilege escalation flaw in Ubiquiti UniFi Protect and urges users to upgrade to version 7.1.83 for remediation.

    00010119
    236 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-55115: UniFi Protect Server-Side Request Forgery Privilege Escalation - What It Means for Your Business and How to Respond https://hubs.li/Q04rKM4h0

    Post summary

    The passage announces CVE‑2026‑55115, highlighting it as a Server‑Side Request Forgery privilege‑escalation in UniFi Protect, without providing concrete evidence of a PoC, exploit, active attack, or patch details.

    0000042
    32 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-55115 Server-Side Request Forgery Privilege Escalation in UniFi Protect Application https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-55115

    Post summary

    The text announces the discovery of a Server‑Side Request Forgery privilege escalation flaw in UniFi Protect (CVE‑2026‑55115) but provides no evidence of exploitation, PoC, or mitigation.

    00000102
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-55115 A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges… https://www.cve.org/CVERecord?id=CVE-2026-55115 ----- Traducción: CVE-2026-55115 Un … http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-55115 as an SSRF flaw in UniFi Protect which could allow privilege escalation, but offers no evidence of exploitation, PoC, patch, or mitigation.

    0000042
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-55115 A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges… https://www.cve.org/CVERecord?id=CVE-2026-55115

    Post summary

    The text announces CVE-2026-55115, describing a Server‑Side Request Forgery in UniFi Protect that may allow privilege escalation. No exploit, PoC, or patch information is provided.

    00000693
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appuiunifi_protect---

Explore more