ZeroHour

CVE-2026-55112

CVSS 3.1
8.8 high
EPSS
<1%p29
Published
()
Modified
Description

A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges on the host device.

Vendors
ui
Products
unifi dream machine pro firmware, unifi dream machine special edition firmware, unifi dream machine pro max firmware, unifi dream machine beast firmware, unifi dream router firmware, unifi dream wall firmware, unifi dream router 7 firmware, unifi cloudkey firmware, unifi network video recorder firmware, unifi network video recorder pro firmware, unifi network video recorder instant firmware, enterprise network video recorder firmware
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.