Description
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Application to access files on the host device.
Published: 2026-07-02
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Path Traversal vulnerability that allows an attacker with network access to read any file on the host device. The flaw results from insufficient validation or sanitisation of file path inputs and is classified as a means thereby compromising the confidentiality of the device and potentially the organization relying on it.

Affected Systems

The vulnerability affects Ubiquiti Inc’s UniFi Access Application. No specific version numbers are disclosed, so all installations that have not applied the vendor’s fix remain vulnerable. The flaw impacts devices connected to the same network as the application.

Risk and Exploitability

Based on the description, the likely attack vector is network-based; the attacker must reach the device over the network or an exposed interface. The CVSS score is 8.6. EPSS score is <1%, suggesting a very low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw allows arbitrary file reads, a successful exploit could reveal configuration data, credentials, or logs and thereby compromise confidentiality.

Generated by OpenCVE AI on July 31, 2026 at 15:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and apply any available vendor updates that address the path traversal flaw.
  • Restrict network access to the UniFi Access Application by applying firewall rules or VPN to limit traffic to trusted hosts.
  • If file handling features are exposed, enforce strict path validation or disable unnecessary file download options, and monitor Ubiquiti’s updates for additional mitigations.

Generated by OpenCVE AI on July 31, 2026 at 15:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Path Traversal in UniFi Access Application Enables Remote File Disclosure

Sat, 25 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Path Traversal in UniFi Access Application Enables Remote File Disclosure

Tue, 21 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Path Traversal in UniFi Access Enables Host File Disclosure

Wed, 15 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Path Traversal in UniFi Access Enables Host File Disclosure

Mon, 13 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Remote File Disclosure via Path Traversal in UniFi Access Application

Sun, 12 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Remote File Disclosure via Path Traversal in UniFi Access Application

Sat, 11 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in UniFi Access Application Allows Unauthorized File Disclosure

Fri, 10 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in UniFi Access Application Allows Unauthorized File Disclosure

Thu, 09 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Path Traversal in Ubiquiti UniFi Access Application Enables Network-Based Information Disclosure

Thu, 09 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Path Traversal in Ubiquiti UniFi Access Application Enables Network-Based Information Disclosure

Wed, 08 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in UniFi Access Application Enabling Information Disclosure

Wed, 08 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in UniFi Access Application Enabling Information Disclosure

Tue, 07 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Unrestricted File Read via Path Traversal in Ubiquiti UniFi Access Application

Mon, 06 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Unrestricted File Read via Path Traversal in Ubiquiti UniFi Access Application

Mon, 06 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Path Traversal in UniFi Access Application Allows File Disclosure

Sun, 05 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Path Traversal in UniFi Access Application Allows File Disclosure

Sun, 05 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Path Traversal in Ubiquiti UniFi Access Application Enables File Disclosure

Sun, 05 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Path Traversal in Ubiquiti UniFi Access Application Enables File Disclosure

Sat, 04 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title UniFi Access Application Path Traversal Vulnerability Enables Host File Disclosure

Sat, 04 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title UniFi Access Application Path Traversal Vulnerability Enables Host File Disclosure

Fri, 03 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Allowing Confidential File Disclosure in UniFi Access Application

Fri, 03 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Path Traversal Allowing Confidential File Disclosure in UniFi Access Application

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Application to access files on the host device.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Ui Unifi Access Application
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-02T15:51:41.293Z

Reserved: 2026-06-16T15:00:01.614Z

Link: CVE-2026-55117

cve-icon Vulnrichment

Updated: 2026-07-02T15:49:25.557Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-02T15:17:05.740

Modified: 2026-07-09T13:19:42.740

Link: CVE-2026-55117

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T15:15:02Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')