
🚨Critical - Ubiquiti UniFi Protect Application SSRF to Privilege Escalation (CVE-2026-55115) A Server-Side Request Forgery flaw in Ubiquiti's UniFi Protect Application lets a network-adjacent attacker with low privileges coerce the application into making attacker-controlled server-side requests. This can be abused to reach internal endpoints and services and to escalate privileges on the underlying host device. Because UniFi Protect runs the camera/NVR surveillance stack, host-level privilege escalation undermines both the appliance and the video infrastructure it manages. The flaw is remotely exploitable with low complexity, needs only a low-privileged account, and requires no user interaction (CVSS 9.9). 👉Upgrade to UniFi Protect Application 7.1.83.
Post summary
The post announces a critical SSRF‑to‑privilege escalation flaw in Ubiquiti UniFi Protect and urges users to upgrade to version 7.1.83 for remediation.




