Summary
CVE-2026-77551 is a critical improper access control vulnerability affecting Ubiquiti’s UniFi Connect Display Cast Pro. The flaw allows a network-accessible attacker to escalate privileges on the device under certain conditions without prior authentication. It carries a CVSS v3.1 base score of 9.0 (Critical), with the vulnerability disclosed by Ubiquiti as part of Security Advisory Bulletin 067.
Technical details
- Root cause: Improper access control (CWE-284) within UniFi Connect Display Cast Pro’s device logic, which fails to properly restrict or validate privilege-related operations.
- Trigger conditions: Exploitation requires specific conditions to be met ("under certain conditions"), as described by Ubiquiti; no user interaction is required.
- Attack vector: Network-based — a malicious actor with network access to the affected device can attempt exploitation remotely, without needing valid credentials (Privileges Required: None).
- Attack complexity: High — successful exploitation depends on conditions or configurations outside the attacker’s direct control.
- Impact: Successful exploitation allows an attacker to escalate privileges on the device, resulting in a scope change and high impact to confidentiality, integrity, and availability of the affected system.
Affected software
- UniFi Connect Display Cast Pro — all versions prior to 1.0.111
Severity
- CVSS v3.1 Base Score: 9.0 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade UniFi Connect Display Cast Pro to version 1.0.111 or later, which contains the fix for this vulnerability.
- If immediate patching is not possible:
- Restrict network access to UniFi Connect Display Cast Pro devices to trusted management networks or VLANs; avoid exposing device management interfaces directly to untrusted or public networks.
- Monitor device and network logs for unexpected privilege changes or anomalous administrative activity.
- Apply network segmentation to isolate UniFi Connect devices from critical infrastructure until the patch can be deployed.

