CVE-2026-55115: SSRF
Published Jul 2, 2026
·Updated
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.
Affected Software
2 affected components
UniFi Protect Application
UI Unifi Protect<7.1.83
Event History
Jul 2, 2026
CVE Published
via MITRE·02:50 PM
Data Sourced
via MITRE·02:50 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeaknessAffected Software
Jul 8, 2026
News Published
via BleepingComputer·08:15 AM
News Published
via BleepingComputer·08:16 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-55115?
The severity of CVE-2026-55115 is critical with a CVSS score of 9.9.
2
How does CVE-2026-55115 exploit the UniFi Protect Application?
CVE-2026-55115 exploits a Server-Side Request Forgery (SSRF) vulnerability allowing privilege escalation.
3
Who is affected by the CVE-2026-55115 vulnerability?
Any malicious actor with low privileges who has access to the network can exploit CVE-2026-55115.
4
What could be the impact of CVE-2026-55115 on the host device?
The impact of CVE-2026-55115 could lead to escalation of privileges on the host device.
5
What version of the UniFi Protect Application is vulnerable to CVE-2026-55115?
The specific version affected by CVE-2026-55115 is not detailed in the provided information, but users should ensure they are updated to mitigate risks.