CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-55115

Critical · CVSS 9.9

UniFi Protect Application — Server-Side Request Forgery (SSRF) leading to privilege escalation

CVSS
9.9
nvd
EPSS
0.23%
14th pct
KEV
No
Class
other
CWE-918

Description

A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.

Search profile — drives PoC discovery

Symbols UniFi ProtectSSRFprivilege escalationCWE-918Security-Advisory-Bulletin-066
Keywords CVE-2026-55115UniFi Protect SSRFUniFi Protect privilege escalationUbiquiti SSRFUniFi Protect Application exploitSecurity Advisory Bulletin 066CWE-918 UniFi

References

Status: enriched · ingested 2026-07-07T18:00:32.000Z · profiled 2026-07-07T18:30:32.000Z