External risk intelligence

UniFi Protect AI Key Improper Access Control Privilege Escalation

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-77557

The vulnerability affects a UniFi Protect AI Key, a network-attached hardware device. While these devices are typically managed within a local network, they can be configured for remote access or cloud-integrated management, making them plausibly reachable from the internet depending on the specific deployment and user configuration.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in UniFi Protect AI Key devices that could allow unauthorized access and privilege escalation for an attacker with network access. This type of issue is significant as it could potentially compromise the integrity and confidentiality of data managed by these devices.

  • Network access allows unauthorized privilege escalation.
  • Critical risk to device integrity and data confidentiality.
  • Confirm device relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker with network access could exploit an improper access control flaw in the UniFi Protect AI Key. This vulnerability allows the attacker to escalate their privileges on the device.

  • No authentication required.
  • Exploits improper access control.
  • Leads to privilege escalation.

Live Threat

Current exploitation, exposure, and threat context

A malicious actor on the network could exploit this vulnerability to gain higher privileges on the UniFi Protect AI Key. This could allow them to control the device and potentially access or modify its behavior when supported by the advisory.

  • Device access and control.
  • Network access allows privilege escalation.
  • Compromised device functionality.

Operational Fix

Recommended remediation, mitigation, and detection steps

To address this critical Improper Access Control vulnerability, system owners and infrastructure teams are primarily responsible for identifying and securing UniFi Protect AI Key devices. The initial, critical step involves pinpointing all deployed AI Key instances, determining their network reachability, assessing their business criticality, and identifying the accountable owner for each device before planning remediation efforts.

  • Infrastructure and security teams own the issue.
  • Verify device network reachability and criticality.
  • Plan targeted remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the UniFi Protect AI Key's role in a network?

The UniFi Protect AI Key is a hardware component within the UniFi ecosystem designed to process video data and manage camera-related functions. It acts as a specialized, network-attached appliance, and its security depends on protecting its management interfaces from unauthorized interaction.

How is the vulnerability in CVE-2026-77557 classified?

This flaw is categorized as CWE-284, which denotes improper access control. It reflects a fundamental failure in the device's security logic where access restrictions are not correctly enforced, allowing entities to perform actions for which they lack authorization.

What enables privilege escalation on the affected hardware?

Privilege escalation is triggered when an attacker possesses network access to the device. Because the system's access controls fail to validate requester permissions, the scope of the vulnerability is not limited to standard user functions, effectively allowing unauthorized elevation to administrative control.

Why is this network-attached device considered a risk?

The Halo Surface Signal scores this as a possible risk because, although these devices typically reside on local networks, they are often configured for remote or cloud-managed access. This potential for internet reachability increases the likelihood that a remote attacker could successfully target the device.

How should infrastructure teams manage this security issue?

Administrators should first conduct an inventory of all UniFi Protect AI Key instances in their environment. Teams must assess the network exposure and business criticality of each unit to prioritize, plan, and execute security hardening measures in coordination with official vendor guidance.

References