CVE-2026-55110
—CVSS 3.1
6.1 medium
EPSS
<1%p19
Published
()
Modified
Description
A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (CORS) misconfiguration found in UniFi OS to trigger actions in UniFi OS using that user's session.
- Vendors
- ui
- Products
- unifi os server, unifi dream machine beast firmware, unifi dream machine pro firmware, unifi dream machine special edition firmware, unifi dream machine pro max firmware, enterprise fortress gateway firmware, unifi dream router firmware, unifi dream wall firmware, unifi dream router 7 firmware, unifi express 7 firmware, unifi cloudkey firmware, unifi cloud key plus firmware
- Weakness
- CWE-942
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.