Description
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.
Published: 2026-07-02
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Improper Access Control flaw (CWE-284) in Ubiquiti Inc's UniFi Access Application. It allows an attacker who already has network connectivity and high local privileges to bypass the application's authorization checks and elevate their privileges on the host device. The description indicates that privilege escalation on the host device is possible; no further impact such as full system compromise or network takeover is detailed.

Affected Systems

The affected product is Ubiquiti Inc's UniFi Access Application. The advisory does not provide specific version information, so any installation running before the release of the corrective update should be inspected against Ubiquiti's security bulletin to confirm whether the patch has been applied.

Risk and Exploitability

The CVSS score of 9.1 indicates, integrity, and availability. The EPSS score is under 1%, suggesting that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to require network access and high local privileges on the host device; the attacker must already have access to the network and privileged rights. Under these conditions, the flaw permits privilege escalation on the host.

Generated by OpenCVE AI on July 21, 2026 at 11:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest UniFi Access Application update released by Ubiquiti to correct the access‑control flaw.
  • Restrict accounts with high local privileges on the device and enforce the principle of least privilege.
  • Segment the network to isolate the UniFi Access subsystem from other traffic, reducing the exposure of privileged accounts.
  • Enable and routinely review logging of privilege‑escalation attempts to detect suspicious activity.

Generated by OpenCVE AI on July 21, 2026 at 11:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Access Application

Wed, 15 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Access Application

Mon, 13 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Access Application

Sun, 12 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Access Application

Sun, 12 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Access Application

Sat, 11 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Access Application

Fri, 10 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Access Allows Privilege Escalation

Thu, 09 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Access Allows Privilege Escalation

Wed, 08 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control Vulnerability Allows Privilege Escalation on UniFi Access Application

Tue, 07 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control Vulnerability Allows Privilege Escalation on UniFi Access Application

Tue, 07 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in Ubiquiti UniFi Access Application

Mon, 06 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in Ubiquiti UniFi Access Application

Mon, 06 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Access Application

Sun, 05 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Access Application

Sun, 05 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control Exploitation in Ubiquiti UniFi Access Application Allows Privilege Escalation

Sat, 04 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control Exploitation in Ubiquiti UniFi Access Application Allows Privilege Escalation

Sat, 04 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Access Application Enables Elevation of Privileges

Sat, 04 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Access Application Enables Elevation of Privileges

Fri, 03 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Access Application

Fri, 03 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Access Application

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-02T16:11:02.050Z

Reserved: 2026-06-13T15:00:00.604Z

Link: CVE-2026-54400

cve-icon Vulnrichment

Updated: 2026-07-02T16:10:57.895Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:15:05Z

Weaknesses