CVE-2026-55110

Published Jul 2, 2026

Last updated 17 days ago

Overview

Description
A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (CORS) misconfiguration found in UniFi OS to trigger actions in UniFi OS using that user's session.
Source
support@hackerone.com
NVD status
Analyzed
Products
unifi_os_server, unifi_dream_machine_beast_firmware, unifi_dream_machine_pro_firmware, unifi_dream_machine_special_edition_firmware, unifi_dream_machine_pro_max_firmware, enterprise_fortress_gateway_firmware, unifi_dream_router_firmware, unifi_dream_wall_firmware, unifi_dream_router_7_firmware, unifi_express_7_firmware, unifi_cloudkey_firmware, unifi_cloud_key_plus_firmware, unifi_cloudkey_enterprise_firmware, unifi_network_video_recorder_firmware, unifi_network_video_recorder_pro_firmware, unifi_network_video_recorder_instant_firmware, enterprise_network_video_recorder_firmware, enterprise_network_video_recorder_core_firmware, unifi_network_video_recorder_g2_firmware, unifi_network_video_recorder_g2_pro_firmware, unifi_cloud_gateway_ultra_firmware, unifi_cloud_gateway_max_firmware, unifi_cloud_gateway_industrial_firmware, unifi_cloud_gateway_fiber_firmware, unas_2_firmware, unas_4_firmware, unas_pro_firmware, unas_pro_4_firmware, unas_pro_8_firmware, enterprise_firewall_core_firmware

Risk scores

CVSS 3.1

Type
Primary
Base score
6.1
Impact score
2.7
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Severity
MEDIUM

Weaknesses

support@hackerone.com
CWE-942
nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending

Configurations