A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerability found in UniFi Protect Application to escalate privileges on the host device.
History

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection in UniFi Protect Elevates Host Privileges

Wed, 22 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection in UniFi Protect Enables Local Privilege Escalation

Fri, 17 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection in UniFi Protect Enables Local Privilege Escalation

Wed, 15 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via SQL Injection in Ubiquiti UniFi Protect

Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via SQL Injection in Ubiquiti UniFi Protect

Sun, 12 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection in UniFi Protect Enables Local Privilege Escalation

Sat, 11 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection in UniFi Protect Enables Local Privilege Escalation

Fri, 10 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title SQL Injection in Ubiquiti UniFi Protect Enables Local Privilege Escalation

Thu, 09 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title SQL Injection in Ubiquiti UniFi Protect Enables Local Privilege Escalation

Thu, 09 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Authenticated SQL Injection in Ubiquiti UniFi Protect

Wed, 08 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Authenticated SQL Injection in Ubiquiti UniFi Protect

Tue, 07 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title SQL Injection in UniFi Protect Allows Local Privilege Escalation

Mon, 06 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title SQL Injection in UniFi Protect Allows Local Privilege Escalation

Mon, 06 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Authenticated SQL Injection in Ubiquiti UniFi Protect

Sun, 05 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Authenticated SQL Injection in Ubiquiti UniFi Protect

Sun, 05 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title SQL Injection in UniFi Protect Enables Local Privilege Escalation

Sun, 05 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title SQL Injection in UniFi Protect Enables Local Privilege Escalation

Sat, 04 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection allows local privilege escalation in Ubiquiti UniFi Protect

Sat, 04 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection allows local privilege escalation in Ubiquiti UniFi Protect

Sat, 04 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection Allows Local Privilege Escalation in UniFi Protect

Fri, 03 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection Allows Local Privilege Escalation in UniFi Protect

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerability found in UniFi Protect Application to escalate privileges on the host device.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2026-07-02T14:50:48.763Z

Updated: 2026-07-02T15:51:17.657Z

Reserved: 2026-06-23T15:00:03.631Z

Link: CVE-2026-56841

cve-icon Vulnrichment

Updated: 2026-07-02T15:41:26.659Z

cve-icon NVD

No data.

cve-icon Redhat

No data.