Sceawere
Vulnerability Detail
CVE-2026-77557UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
UniFi Protect AI Key Privilege Escalation
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 8h ago
- Vendor
- Ubiquiti Inc
- Product
- UniFi Protect AI Key
- Attack Type
- CWE-284 Improper Access Control - Generic
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalate privileges on the device.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-08-26T11:16:39.520Z",
"pubdate": "2026-08-26T11:16:39.520Z",
"executiveSummary": "A critical Improper Access Control vulnerability exists within the UniFi Protect AI Key, enabling authenticated network attackers to escalate privileges on the affected hardware.\nThe vulnerability stems from flawed access control enforcement, which allows unauthorized manipulation of system-level permissions.\nSuccessful exploitation grants an attacker elevated administrative rights, potentially compromising the integrity, confidentiality, and availability of the device.\nThis vulnerability is particularly severe as it resides on the physical access control hardware, where gaining administrative control could facilitate further unauthorized physical facility access.\nExploitation requires the attacker to have established network access to the target device.\nOrganizations deploying UniFi Protect AI Key should prioritize restricting network access to the management interface and monitoring for anomalous privilege escalation attempts.",
"technicalDetails": "The vulnerability is classified as an Improper Access Control flaw within the UniFi Protect AI Key authorization logic. At its core, the issue resides in the insufficient validation of user-supplied requests when interacting with internal API endpoints responsible for role-based access control (RBAC) and authorization management.\nThe root cause is identified as a failure to strictly enforce access policy checks on critical configuration functions. Specifically, the system fails to correctly verify the privilege level of the authenticated user when processing requests that modify system permission sets or account attributes. Because the access control mechanism is bypassable, an attacker with valid, low-privileged credentials—or potentially unauthenticated access depending on specific endpoint visibility—can submit malformed requests to manipulate their own authorization context.\nThe attack flow commences with the adversary establishing connectivity to the UniFi Protect AI Key management network. Once the initial network connection is established, the attacker probes the backend API for exposed interfaces. By identifying specific endpoints that govern user management or permission assignment, the attacker constructs a crafted HTTP request designed to promote their existing session privilege level.\nDue to the lack of server-side state verification, the device processes the unauthorized request and updates the internal access control list (ACL) or the associated session token in memory to reflect administrative privileges. This elevation of privilege allows the attacker to execute arbitrary administrative commands that would otherwise be restricted, including the ability to manage connected locks, view sensitive event logs, and alter global security parameters.\nPost-exploitation impact includes full administrative control over the AI Key device. Given the function of the UniFi Protect AI Key in security ecosystems, this level of access may allow an attacker to trigger physical ingress/egress points by manipulating lock state configurations, disabling security alerts, or deleting forensic evidence of unauthorized access. The vulnerability exposes the device to persistent configuration changes, allowing for potential backdoor installation or long-term credential harvesting from the device's management database.\nThe exploitation mechanism leverages the device's trust in client-side input for sensitive operations, circumventing the intended defensive boundary between user and administrator roles."
}