CVE-2026-77536
9.9Ubiquiti · UniFi OS Server
An improper access control vulnerability in Ubiquiti UniFi OS allows low-privileged network users to escalate privileges and achieve full system control.
Executive summary
A critical privilege escalation vulnerability in Ubiquiti UniFi OS devices permits authenticated attackers to gain administrative control, posing a severe risk to network infrastructure.
Vulnerability
The flaw is an Improper Access Control vulnerability (CWE-284) that allows a low-privileged, network-authenticated user to bypass authorization checks and perform actions with elevated administrative privileges.
Business impact
The exploitation of this vulnerability results in a total compromise of the affected device, allowing an attacker to manipulate network traffic, access video surveillance streams, or reconfigure security settings. Given the CVSS score of 9.9, the potential for unauthorized administrative access represents a critical threat to the confidentiality, integrity, and availability of the entire network environment.
Remediation
Immediate Action: Update affected UniFi OS devices to the specified patched versions (5.1.37 for UniFi OS Server or 5.1.31 for other listed hardware) immediately.
Proactive Monitoring: Review system and audit logs for unauthorized configuration changes or unexpected administrative sessions initiated by low-privileged accounts.
Compensating Controls: Restrict management interface access to trusted, isolated management networks and employ network segmentation to limit the number of users who can reach the UniFi OS web interface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Due to the critical nature of this vulnerability and the potential for full system takeover, administrators should prioritize patching all UniFi OS devices within their inventory. If immediate patching is not feasible, ensure that administrative interfaces are not exposed to the public internet and limit access to the affected devices to strictly authenticated, trusted personnel.