CVE-2026-55115
Critical · CVSS 9.9UniFi Protect Application — Server-Side Request Forgery (SSRF) leading to privilege escalation
- CVSS
- 9.9
- nvd
- EPSS
- 0.23%
- 14th pct
- KEV
- No
- Class
- other
- CWE-918
Description
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.
Search profile — drives PoC discovery
Symbols UniFi ProtectSSRFprivilege escalationCWE-918Security-Advisory-Bulletin-066
Keywords CVE-2026-55115UniFi Protect SSRFUniFi Protect privilege escalationUbiquiti SSRFUniFi Protect Application exploitSecurity Advisory Bulletin 066CWE-918 UniFi
References
Status: enriched · ingested 2026-07-07T18:00:32.000Z · profiled 2026-07-07T18:30:32.000Z