CVE-2026-55112: UI Enterprise Network Video Recorder Core Firmware
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges on the host device.
Affected products
- UI Enterprise Network Video Recorder Core Firmware: up to and including 5.1.15
- UI Enterprise Network Video Recorder Firmware: up to and including 5.1.15
- UI UniFi Cloud Gateway Fiber Firmware: up to and including 5.1.15
- UI UniFi Cloud Gateway Industrial Firmware: up to and including 5.1.15
- UI UniFi Cloud Gateway Max Firmware: up to and including 5.1.15
- UI UniFi Cloudkey Firmware: up to and including 5.1.15
- UI UniFi Dream Machine Beast Firmware: up to and including 5.1.15
- UI UniFi Dream Machine Pro Firmware: up to and including 5.1.15
- UI UniFi Dream Machine Pro Max Firmware: up to and including 5.1.15
- UI UniFi Dream Machine Special Edition Firmware: up to and including 5.1.15
- UI UniFi Dream Router 5g Max Firmware: up to and including 5.1.15
- UI UniFi Dream Router 7 Firmware: up to and including 5.1.15
- UI UniFi Dream Router Firmware: up to and including 5.1.15
- UI UniFi Dream Wall Firmware: up to and including 5.1.15
- UI UniFi Network Video Recorder Firmware: up to and including 5.1.15
- UI UniFi Network Video Recorder g2 Firmware: up to and including 5.1.15
- UI UniFi Network Video Recorder g2 Pro Firmware: up to and including 5.1.15
- UI UniFi Network Video Recorder Instant Firmware: up to and including 5.1.15
- UI UniFi Network Video Recorder Pro Firmware: up to and including 5.1.15
Published 2026-07-02. Last modified 2026-07-10.