CVE Feed

    Dashboard / CVE / CVE-2026-55110

    CVE-2026-55110

    A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (CORS) misconfiguration found in UniFi OS to trigger actions in UniFi OS using that user's session.

    Published:Jul 2, 2026
    Last Modified:Aug 13, 2026
    EPS:Jul 2, 2026
    EPSS Score:0.00148
    CVSS Score:7.5

    Affected Products

    Vendor
    Ui
    Product
    Enterprise Firewall Core
    Vendor
    Ui
    Product
    Enterprise Firewall Core Firmware
    Vendor
    Ui
    Product
    Enterprise Fortress Gateway
    Vendor
    Ui
    Product
    Enterprise Fortress Gateway Firmware
    Vendor
    Ui
    Product
    Enterprise Network Video Recorder
    Vendor
    Ui
    Product
    Enterprise Network Video Recorder Core
    Vendor
    Ui
    Product
    Enterprise Network Video Recorder Core Firmware
    Vendor
    Ui
    Product
    Enterprise Network Video Recorder Firmware
    Vendor
    Ui
    Product
    Unas 2
    Vendor
    Ui
    Product
    Unas 2 Firmware
    Vendor
    Ui
    Product
    Unas 4
    Vendor
    Ui
    Product
    Unas 4 Firmware
    Vendor
    Ui
    Product
    Unas Pro
    Vendor
    Ui
    Product
    Unas Pro 4
    Vendor
    Ui
    Product
    Unas Pro 4 Firmware
    Vendor
    Ui
    Product
    Unas Pro 8
    Vendor
    Ui
    Product
    Unas Pro 8 Firmware
    Vendor
    Ui
    Product
    Unas Pro Firmware
    Vendor
    Ui
    Product
    Unifi Cloud Gateway Fiber
    Vendor
    Ui
    Product
    Unifi Cloud Gateway Fiber Firmware
    Vendor
    Ui
    Product
    Unifi Cloud Gateway Industrial
    Vendor
    Ui
    Product
    Unifi Cloud Gateway Industrial Firmware
    Vendor
    Ui
    Product
    Unifi Cloud Gateway Max
    Vendor
    Ui
    Product
    Unifi Cloud Gateway Max Firmware
    Vendor
    Ui
    Product
    Unifi Cloud Gateway Ultra
    Vendor
    Ui
    Product
    Unifi Cloud Gateway Ultra Firmware
    Vendor
    Ui
    Product
    Unifi Cloud Key Plus
    Vendor
    Ui
    Product
    Unifi Cloud Key Plus Firmware
    Vendor
    Ui
    Product
    Unifi Cloudkey
    Vendor
    Ui
    Product
    Unifi Cloudkey Enterprise
    Vendor
    Ui
    Product
    Unifi Cloudkey Enterprise Firmware
    Vendor
    Ui
    Product
    Unifi Cloudkey Firmware
    Vendor
    Ui
    Product
    Unifi Dream Machine Beast
    Vendor
    Ui
    Product
    Unifi Dream Machine Beast Firmware
    Vendor
    Ui
    Product
    Unifi Dream Machine Pro
    Vendor
    Ui
    Product
    Unifi Dream Machine Pro Firmware
    Vendor
    Ui
    Product
    Unifi Dream Machine Pro Max
    Vendor
    Ui
    Product
    Unifi Dream Machine Pro Max Firmware
    Vendor
    Ui
    Product
    Unifi Dream Machine Special Edition
    Vendor
    Ui
    Product
    Unifi Dream Machine Special Edition Firmware
    Vendor
    Ui
    Product
    Unifi Dream Router
    Vendor
    Ui
    Product
    Unifi Dream Router 7
    Vendor
    Ui
    Product
    Unifi Dream Router 7 Firmware
    Vendor
    Ui
    Product
    Unifi Dream Router Firmware
    Vendor
    Ui
    Product
    Unifi Dream Wall
    Vendor
    Ui
    Product
    Unifi Dream Wall Firmware
    Vendor
    Ui
    Product
    Unifi Express 7
    Vendor
    Ui
    Product
    Unifi Express 7 Firmware
    Vendor
    Ui
    Product
    Unifi Network Video Recorder
    Vendor
    Ui
    Product
    Unifi Network Video Recorder Firmware
    Vendor
    Ui
    Product
    Unifi Network Video Recorder G2
    Vendor
    Ui
    Product
    Unifi Network Video Recorder G2 Firmware
    Vendor
    Ui
    Product
    Unifi Network Video Recorder G2 Pro
    Vendor
    Ui
    Product
    Unifi Network Video Recorder G2 Pro Firmware
    Vendor
    Ui
    Product
    Unifi Network Video Recorder Instant
    Vendor
    Ui
    Product
    Unifi Network Video Recorder Instant Firmware
    Vendor
    Ui
    Product
    Unifi Network Video Recorder Pro
    Vendor
    Ui
    Product
    Unifi Network Video Recorder Pro Firmware
    Vendor
    Ui
    Product
    Unifi Os Server

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High