CVE-2026-77534

9.9

Ubiquiti · UniFi OS Server

An improper access control vulnerability in Ubiquiti UniFi OS allows an attacker with low privileges to escalate their access level within the device.

Executive summary

A critical improper access control vulnerability in multiple Ubiquiti UniFi OS devices allows low-privileged network users to achieve full privilege escalation and system compromise.

Vulnerability

The vulnerability, categorized as CWE-284, involves improper access control within the UniFi OS environment. An attacker who has achieved low-level authenticated access to the network can exploit this flaw to bypass standard authorization checks and escalate privileges to the highest level.

Business impact

The potential impact of this vulnerability is severe, as it enables full administrative control over network infrastructure and management appliances. Given the CVSS score of 9.9, this represents a critical risk that could lead to complete unauthorized access to sensitive management interfaces, data exfiltration, or the disruption of critical network services.

Remediation

Immediate Action: Update all affected Ubiquiti UniFi OS devices to version 5.1.37 or 5.1.31 as specified by the vendor advisory to eliminate the vulnerable code path.

Proactive Monitoring: Monitor system access logs for anomalous login patterns or unexpected privilege changes occurring from low-privileged user accounts.

Compensating Controls: Restrict access to UniFi management interfaces to trusted management subnets or VPNs to limit the exposure of the vulnerable endpoint to internal users only.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability presents a catastrophic risk to network availability and integrity due to the potential for total system compromise. Administrators must prioritize the installation of the vendor-provided firmware updates immediately across all affected hardware, including Dream Machines and NVR units, to prevent unauthorized administrative access.

More Ubiquiti CVEs

Sources