CVE-2026-55112
published 2026-07-02CVE-2026-55112: A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in…
PriorityP358high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.36%
29.3th percentile
A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges on the host device.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ubiquiti_inc | cloud_gateways | < 5.1.19 | 5.1.19 |
| ubiquiti_inc | cloud_keys | < 5.1.19 | 5.1.19 |
| ubiquiti_inc | dream_machines | < 5.1.19 | 5.1.19 |
| ubiquiti_inc | dream_routers | < 5.1.19 | 5.1.19 |
| ubiquiti_inc | dream_wall | < 5.1.19 | 5.1.19 |
| ubiquiti_inc | enterprise_video_recorders | < 5.1.19 | 5.1.19 |
| ubiquiti_inc | network_video_recorders | < 5.1.19 | 5.1.19 |
| ui | enterprise_network_video_recorder_core_firmware | <= 5.1.15 | — |
| ui | enterprise_network_video_recorder_firmware | <= 5.1.15 | — |
| ui | unifi_cloud_gateway_fiber_firmware | <= 5.1.15 | — |
| ui | unifi_cloud_gateway_industrial_firmware | <= 5.1.15 | — |
| ui | unifi_cloud_gateway_max_firmware | <= 5.1.15 | — |
| ui | unifi_cloudkey_firmware | <= 5.1.15 | — |
| ui | unifi_dream_machine_beast_firmware | <= 5.1.15 | — |
| ui | unifi_dream_machine_pro_firmware | <= 5.1.15 | — |
| ui | unifi_dream_machine_pro_max_firmware | <= 5.1.15 | — |
| ui | unifi_dream_machine_special_edition_firmware | <= 5.1.15 | — |
| ui | unifi_dream_router_5g_max_firmware | <= 5.1.15 | — |
| ui | unifi_dream_router_7_firmware | <= 5.1.15 | — |
| ui | unifi_dream_router_firmware | <= 5.1.15 | — |
| ui | unifi_dream_wall_firmware | <= 5.1.15 | — |
| ui | unifi_network_video_recorder_firmware | <= 5.1.15 | — |
| ui | unifi_network_video_recorder_g2_firmware | <= 5.1.15 | — |
| ui | unifi_network_video_recorder_g2_pro_firmware | <= 5.1.15 | — |
| ui | unifi_network_video_recorder_instant_firmware | <= 5.1.15 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Ubiquiti Dream Machines prior 5.1.19 access control
vuldb·2026-07-02·CVSS 7.5
CVE-2026-55112 [HIGH] Ubiquiti Dream Machines prior 5.1.19 access control
A vulnerability marked as critical has been reported in Ubiquiti Dream Machines, Dream Wall, Dream Routers, Cloud Keys, Network Video Recorders, Enterprise Video Recorders and Cloud Gateways. The affected element is an unknown function. The manipulation leads to improper access controls.
This vulnerability is listed as CVE-2026-55112. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
GHSA
A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to
ghsa_unreviewed·2026-07-02
CVE-2026-55112 [HIGH] CWE-284 A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to
A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges on the host device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-02
Published