CVE-2026-77545 PUBLISHED

Assigner: Ubiquiti
Reserved: 20.08.2026 Published: 26.08.2026 Updated: 26.08.2026

A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CVSS Score: 9

Product Status

Vendor Ubiquiti Inc
Product UniFi OS Server
Versions Default: unaffected
  • affected from 0 to 5.1.37 (excl.)
Vendor Ubiquiti Inc
Product Cloud Keys
Versions Default: unaffected
  • affected from 0 to 5.1.31 (excl.)
Vendor Ubiquiti Inc
Product Network Video Recorders
Versions Default: unaffected
  • affected from 0 to 5.1.31 (excl.)
Vendor Ubiquiti Inc
Product Enterprise Network Video Recorders
Versions Default: unaffected
  • affected from 0 to 5.1.31 (excl.)
Vendor Ubiquiti Inc
Product Enterprise Network Attached Storage
Versions Default: unaffected
  • affected from 0 to 5.1.31 (excl.)
Vendor Ubiquiti Inc
Product Dream Machines
Versions Default: unaffected
  • affected from 0 to 5.1.31 (excl.)
Vendor Ubiquiti Inc
Product Enterprise Firewall Core
Versions Default: unaffected
  • affected from 0 to 5.1.31 (excl.)
Vendor Ubiquiti Inc
Product Dream Routers
Versions Default: unaffected
  • affected from 0 to 5.1.31 (excl.)
Vendor Ubiquiti Inc
Product Enterprise Fortress Gateway
Versions Default: unaffected
  • affected from 0 to 5.1.31 (excl.)
Vendor Ubiquiti Inc
Product Cloud Gateways
Versions Default: unaffected
  • affected from 0 to 5.1.31 (excl.)
Vendor Ubiquiti Inc
Product Dream Wall
Versions Default: unaffected
  • affected from 0 to 5.1.31 (excl.)
Vendor Ubiquiti Inc
Product Express 7
Versions Default: unaffected
  • affected from 0 to 5.1.31 (excl.)
Vendor Ubiquiti Inc
Product Network Attached Storage
Versions Default: unaffected
  • affected from 0 to 5.1.32 (excl.)

References

Problem Types

  • CWE-489 Active debug code CWE