CVE-2026-77536: Ubiquiti Inc Cloud Gateways

Critical severity, CVSS 9.9. EPSS: 0.4% chance of exploitation in the next 30 days.

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.

Affected products

  • Ubiquiti Inc Cloud Gateways: before 5.1.31 (fixed in 5.1.31)
  • Ubiquiti Inc Cloud Keys: before 5.1.31 (fixed in 5.1.31)
  • Ubiquiti Inc Dream Machines: before 5.1.31 (fixed in 5.1.31)
  • Ubiquiti Inc Dream Routers: before 5.1.31 (fixed in 5.1.31)
  • Ubiquiti Inc Dream Wall: before 5.1.31 (fixed in 5.1.31)
  • Ubiquiti Inc Enterprise Firewall Core: before 5.1.31 (fixed in 5.1.31)
  • Ubiquiti Inc Enterprise Fortress Gateway: before 5.1.31 (fixed in 5.1.31)
  • Ubiquiti Inc Enterprise Network Attached Storage: before 5.1.31 (fixed in 5.1.31)
  • Ubiquiti Inc Enterprise Network Video Recorders: before 5.1.31 (fixed in 5.1.31)
  • Ubiquiti Inc Express 7: before 5.1.31 (fixed in 5.1.31)
  • Ubiquiti Inc Network Attached Storage: before 5.1.32 (fixed in 5.1.32)
  • Ubiquiti Inc Network Video Recorders: before 5.1.31 (fixed in 5.1.31)
  • Ubiquiti Inc UniFi OS Server: before 5.1.37 (fixed in 5.1.37)

Published 2026-08-26. Last modified 2026-08-28.