CVE-2026-77545
A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
- EPSS probability
- 0.21%
- CWE
- CWE-489
- Published
- 2026-08-26
- Last modified
- 2026-08-27
Affected products
- Ubiquiti Inc UniFi OS Server
- Ubiquiti Inc Cloud Keys
- Ubiquiti Inc Network Video Recorders
- Ubiquiti Inc Enterprise Network Video Recorders
- Ubiquiti Inc Enterprise Network Attached Storage
- Ubiquiti Inc Dream Machines
- Ubiquiti Inc Enterprise Firewall Core
- Ubiquiti Inc Dream Routers
Weakness type
Related vulnerabilities
- CVE-2026-6485 — UEFI BIOS embedded Shell can be used to bypass Secure Boot
- CVE-2026-66787 — Lighthouse: go pprof profiling endpoint enabled unconditionally on lighthouse-agent :8082
- CVE-2026-66405 — DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be...
- CVE-2026-66403 — DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor...
- CVE-2026-41186 — Unauthenticated Go pprof exposure in Calico debug server
- CVE-2026-65893 — Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
- CVE-2026-58378 — Allwinner TV Box TV98 ADB exposed on network
- CVE-2026-54799 — A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions <...