A critical Server-Side Request Forgery (SSRF) vulnerability has been identified in the UniFi Protect application, designated as CVE-2026-55115. This vulnerability allows an attacker with network access and low privileges to escalate their privileges on the host device. The CVSS score of 9.9 indicates a severe risk level, emphasizing the urgency of mitigation. The vulnerability affects the UniFi Protect software, which is widely used for surveillance and security management. Exploitation of this flaw could lead to unauthorized access, data breaches, and potential system compromise. Organizations and individuals using UniFi Protect are strongly advised to apply the latest security patches provided by the vendor to mitigate this risk. Until a patch is applied, users should restrict network access to the UniFi Protect application and monitor for any suspicious activity. It is crucial to maintain up-to-date software to protect against emerging threats and ensure the integrity of security systems.
CRITICAL
CVSS 9.9
CVE-2026-55115
2026-08-23
Critical SSRF Vulnerability in UniFi Protect Application (CVE-2026-55115)
A critical Server-Side Request Forgery (SSRF) vulnerability in UniFi Protect allows privilege escalation. CVSS 9.9. Affected users should apply patches immediately to prevent unauthorized access and system compromise.