Description
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.
Published: 2026-07-02
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An Improper Access Control flaw (CWE‑284) exists in Ubiquiti Inc’s UniFi Network Application. The vulnerability allows an attacker who has network reachability and basic user credentials to increase their privileges within the application. Based on the description, it is inferred that the attacker could modify network configurations, access restricted data, or disrupt services once the privilege escalation succeeds. The consequences are not explicitly stated but represent logical outcomes of elevated privileges.

Affected Systems

The vulnerability impacts Ubiquiti Inc’s UniFi Network Application. No specific product versions are identified, implying that all versions prior to a vendor‑issued fix may be affected. Any deployment of the UniFi management console that is accessible over a network is potentially vulnerable, especially if low‑privileged accounts exist.

Risk and Exploitability

CVSS scoring of 8.8 signals a high severity flaw. The EPSS score of < 1% suggests that active exploitation is currently rare. The vulnerability is not listed in CISA KEV. The likely attack path involves an attacker with network access and a low‑privileged user account exploiting missing permission checks in the application to elevate privileges. The necessity of network reachability indicates that protecting the management interface and enforcing strict access controls are critical.

Generated by OpenCVE AI on July 21, 2026 at 11:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the UniFi Network Application to the latest version that includes the vendor‑issued fix
  • Restrict access to the UniFi management console by configuring firewall rules, VLAN segregation, or equivalent network controls
  • Eliminate or tightly restrict low‑privileged user accounts and enforce the principle of least privilege within the application

Generated by OpenCVE AI on July 21, 2026 at 11:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Network Application

Wed, 15 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in Ubiquiti UniFi Network Application

Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in Ubiquiti UniFi Network Application

Sun, 12 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Network Application Allows Privilege Escalation

Sat, 11 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Network Application Allows Privilege Escalation

Fri, 10 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Network Application

Thu, 09 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Network Application

Wed, 08 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in Ubiquiti UniFi Network Application

Tue, 07 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in Ubiquiti UniFi Network Application

Mon, 06 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Network Application Enables Privilege Escalation

Mon, 06 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Network Application Enables Privilege Escalation

Sun, 05 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control Allows Privilege Escalation in UniFi Network Application

Sun, 05 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control Allows Privilege Escalation in UniFi Network Application

Sun, 05 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Network Application Enables Privilege Escalation

Sat, 04 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Network Application Enables Privilege Escalation

Sat, 04 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Network Application

Sat, 04 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Network Application

Fri, 03 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Network Application

Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Network Application

Thu, 02 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Ubiquiti
Ubiquiti unifi Network Application
Vendors & Products Ubiquiti
Ubiquiti unifi Network Application

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ubiquiti Unifi Network Application
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-02T15:51:04.788Z

Reserved: 2026-06-16T15:00:01.614Z

Link: CVE-2026-55114

cve-icon Vulnrichment

Updated: 2026-07-02T15:41:22.549Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:15:05Z

Weaknesses