CVE-2026-77534 PUBLISHED

Assigner: Ubiquiti
Reserved: 20.08.2026 Published: 26.08.2026 Updated: 26.08.2026

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.9

Product Status

Vendor Ubiquiti Inc
Product UniFi OS Server
Versions Default: unaffected
  • affected from 0 to 5.1.37 (excl.)
Vendor Ubiquiti Inc
Product Cloud Keys
Versions Default: unaffected
  • affected from 0 to 5.1.31 (excl.)
Vendor Ubiquiti Inc
Product Network Video Recorders
Versions Default: unaffected
  • affected from 0 to 5.1.31 (excl.)
Vendor Ubiquiti Inc
Product Enterprise Network Video Recorders
Versions Default: unaffected
  • affected from 0 to 5.1.31 (excl.)
Vendor Ubiquiti Inc
Product Enterprise Network Attached Storage
Versions Default: unaffected
  • affected from 0 to 5.1.31 (excl.)
Vendor Ubiquiti Inc
Product Dream Machines
Versions Default: unaffected
  • affected from 0 to 5.1.31 (excl.)
Vendor Ubiquiti Inc
Product Enterprise Firewall Core
Versions Default: unaffected
  • affected from 0 to 5.1.31 (excl.)
Vendor Ubiquiti Inc
Product Dream Routers
Versions Default: unaffected
  • affected from 0 to 5.1.31 (excl.)
Vendor Ubiquiti Inc
Product Enterprise Fortress Gateway
Versions Default: unaffected
  • affected from 0 to 5.1.31 (excl.)
Vendor Ubiquiti Inc
Product Cloud Gateways
Versions Default: unaffected
  • affected from 0 to 5.1.31 (excl.)
Vendor Ubiquiti Inc
Product Dream Wall
Versions Default: unaffected
  • affected from 0 to 5.1.31 (excl.)
Vendor Ubiquiti Inc
Product Express 7
Versions Default: unaffected
  • affected from 0 to 5.1.31 (excl.)
Vendor Ubiquiti Inc
Product Network Attached Storage
Versions Default: unaffected
  • affected from 0 to 5.1.32 (excl.)

References

Problem Types

  • CWE-284 Improper Access Control - Generic CWE