Sceawere
Vulnerability Detail
CVE-2026-77551UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
UniFi Connect Display Improper Access
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9
- Creation Date
- 8h ago
- Vendor
- Ubiquiti Inc
- Product
- UniFi Connect Display Cast Pro
- Attack Type
- CWE-284 Improper Access Control - Generic
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Connect Display Cast Pro to escalate privileges on the device.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.0",
"pubDate": "2026-08-26T11:16:39.053Z",
"pubdate": "2026-08-26T11:16:39.053Z",
"executiveSummary": "This vulnerability involves an Improper Access Control flaw within the UniFi Connect Display Cast Pro, which facilitates privilege escalation by unauthorized actors.\nThe vulnerability allows a malicious actor who has already gained network access to the device to bypass intended security constraints and escalate their privileges.\nThe potential impact of successful exploitation includes full administrative control over the affected device, potentially leading to unauthorized data access, system manipulation, or further persistence within the network.\nThe risk is considered significant due to the nature of privilege escalation, which undermines the core security boundary of the device firmware.\nExploitation requires the attacker to have established network connectivity to the target device and to meet specific, as-yet-defined conditions inherent to the device's operational state.\nNo authentication is required to initiate the exploitation process, provided the attacker meets the necessary network and conditional criteria.",
"technicalDetails": "The core of the vulnerability lies in an Improper Access Control flaw (CWE-284) within the UniFi Connect Display Cast Pro firmware, which permits an attacker to perform unauthorized operations that should be restricted based on current user privileges.\nThe vulnerability manifests because the device fails to adequately validate or enforce access control policies across all internal service calls or interfaces exposed to the network, allowing an actor to invoke restricted administrative functions.\nExploitation initiates when an attacker, positioned on the local network segment, interacts with the affected component of the UniFi Connect Display Cast Pro. The attack does not require prior valid credentials, indicating a failure in the initial authorization check of the interface.\nThe attack flow follows a structured path where the attacker crafts specific requests that target the identified vulnerable component. By leveraging the Improper Access Control, the attacker manipulates internal mechanisms to bypass standard security authorization headers or session validation checks.\nOnce the initial request is accepted by the vulnerable component, the system erroneously elevates the attacker's context, granting permissions usually reserved for administrative roles. This elevation bypasses the intended multi-tiered access control model implemented by the vendor.\nPost-exploitation, the attacker possesses elevated privileges, enabling them to alter device configurations, execute unauthorized binary code, or extract sensitive system information. This capability can be leveraged to compromise the integrity and confidentiality of the device operations.\nThe lack of strict validation at the API or functional level enables an attacker to influence system behavior beyond the scope of their legitimate access level, thereby establishing a pathway for full system compromise.\nThe vulnerable component exhibits insufficient hardening regarding inter-process communication or external request verification, allowing the improper escalation to occur when specific conditions are met during the request lifecycle.\nThis vulnerability highlights a critical failure in the Principle of Least Privilege, as the underlying architecture does not sufficiently compartmentalize administrative functions from general-purpose or user-accessible interfaces, resulting in a direct escalation path for network-based attackers."
}