CVE-2026-77551
Summary
| CVE | CVE-2026-77551 |
|---|---|
| State | PUBLISHED |
| Assigner | Ubiquiti |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-26 11:16:39 UTC |
| Updated | 2026-08-28 18:49:15 UTC |
| Description | A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Connect Display Cast Pro to escalate privileges on the device. |
Risk And Classification
Primary CVSS: v3.1 9 CRITICAL from fe490ce8-0395-4072-90d8-2707e1bdf984
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS: 0.002200000 probability, percentile 0.123900000 (date 2026-08-30)
Problem Types: CWE-284 | CWE-284 CWE-284 Improper Access Control - Generic
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | fe490ce8-0395-4072-90d8-2707e1bdf984 | Secondary | 9 | CRITICAL | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 9 | CRITICAL | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Ubiquiti Inc | UniFi Connect Display Cast Pro | affected 1.0.111 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8b... | fe490ce8-0395-4072-90d8-2707e1bdf984 | community.ui.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.