CVE-2026-55115 -- CVSS 9.9 Vulnerability Briefing
CVE-2026-55115 | CVSS 9.9 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-55115 is a Server-Side Request Forgery (SSRF) vulnerability in Ubiquiti's UniFi Protect application that allows a low-privileged network-adjacent attacker to escalate privileges on the underlying host device.
Technical Detail
The flaw exists within the UniFi Protect application and can be triggered by an authenticated attacker with low privileges who has access to the network segment hosting the application. By crafting malicious requests that abuse the server-side request mechanism, the attacker can cause the application to make unauthorized internal requests, which can be leveraged to escalate privileges on the host device. The impact is significant: successful exploitation could grant an attacker elevated or administrative control over the host system running UniFi Protect, potentially compromising the broader network surveillance infrastructure managed by the application.
Exploitation Status
No known exploit code has been publicly identified or confirmed at this time. The vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities catalog. Despite the absence of confirmed exploitation, the critical CVSS score of 9.9 and the relatively low barrier to entry (low privileges, network access) make this a high-priority concern for organizations running UniFi Protect.
Who Is Targeting This
No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with this vulnerability as of July 09, 2026.
What To Do
Organizations running UniFi Protect should apply any available patches from Ubiquiti immediately, prioritizing this update given the critical severity rating and privilege escalation impact. Administrators should check the Ubiquiti security advisory portal for the patched version of UniFi Protect and update all affected deployments without delay. As an interim measure, restrict network access to the UniFi Protect management interface to trusted hosts and VLANs only, reducing the pool of potential attackers who could meet the network access prerequisite. Monitor application and host-level logs for anomalous outbound requests originating from the UniFi Protect process, unexpected privilege changes, or unusual internal network traffic patterns that could indicate SSRF abuse. Given that this vulnerability requires only low privileges to exploit, any authenticated user account on the platform should be treated as a potential risk vector until patching is complete.