Junglewise Threat Intelligence

CVE-2026-56841: Ubiquiti UniFi Protect SQL injection privilege escalation

CVE-2026-56841 · Severity: high · CVSS 8.8 · Published 2026-07-02

Technologies: Ubiquiti UniFi Protect. Vendors: Ubiquiti Inc, Ubiquiti.

Executive brief

Ubiquiti UniFi Protect is a video surveillance management system used to monitor and record security camera footage. A security vulnerability has been identified that allows a user with low-level access to the system to gain full administrative control over the host device. This could lead to unauthorized access to sensitive video data, disruption of security monitoring, or complete compromise of the underlying hardware.

Technical details

An authenticated SQL injection vulnerability (CWE-89) exists in the Ubiquiti UniFi Protect Application prior to version 7.1.83. The flaw allows a network-adjacent or remote attacker with low-level authenticated credentials to inject malicious SQL commands into application queries. Successful exploitation enables the attacker to escalate their privileges to a higher level on the host device, potentially gaining full system access. The vulnerability is addressed in UniFi Protect Application version 7.1.83.

Affected products

  • Ubiquiti Inc UniFi Protect Application < 7.1.83

Timeline

  • 2026-07-02: disclosed
  • 2026-07-02: advisory

References

Related threats