CVE-2026-77557
9.8Ubiquiti · UniFi Protect AI Key
An improper access control vulnerability in the Ubiquiti UniFi Protect AI Key allows unauthenticated network actors to escalate privileges on the affected device.
Executive summary
A critical privilege escalation vulnerability in the Ubiquiti UniFi Protect AI Key allows unauthenticated network attackers to gain full administrative control over the device.
Vulnerability
This flaw is an improper access control issue (CWE-284) that enables an unauthenticated attacker, with network access to the device, to bypass security boundaries and escalate privileges.
Business impact
The ability for an unauthenticated user to escalate privileges on a network security device presents a severe risk to organizational infrastructure. Given the CVSS score of 9.8, this vulnerability could lead to a complete compromise of the device, potentially allowing attackers to pivot into the internal network, intercept video feeds, or disable security monitoring capabilities, resulting in significant operational and security risks.
Remediation
Immediate Action: Update the Ubiquiti UniFi Protect AI Key firmware to version 2.2.6 or later immediately to resolve the improper access control flaw.
Proactive Monitoring: Review device access logs for unauthorized administrative logins or anomalous configuration changes that deviate from established baselines.
Compensating Controls: Ensure the UniFi Protect AI Key is placed on a segmented management network with strict firewall rules to limit access to authorized personnel only, effectively mitigating the network accessibility required for exploitation.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability is classified as critical due to the potential for full system compromise by unauthenticated actors. Security teams must prioritize the deployment of the vendor-provided firmware update across all affected UniFi Protect AI Key units to eliminate the risk of unauthorized privilege escalation.