Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-55115: UniFi Protect Application SSRF Privilege Escalation Risk

CVE-2026-55115 CVE-2026-55115
Summary

The UniFi Protect Application is at risk of a security breach if a malicious actor can access the network. This could allow them to gain more control over the host device. To protect against this, ensure the UniFi Protect Application is installed and configured securely, and implement network access controls to limit who can access the application.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
ubiquiti inc unifi protect application < 7.1.83
Original title
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.
Original description
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.
mitre CVSS3.1 9.9
Vulnerability type
CWE-918 Server-Side Request Forgery (SSRF)
Published: 2 Jul 2026 · Updated: 20 Jul 2026 · First seen: 2 Jul 2026