Description
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Application to access files on the host device.
Published: 2026-07-02
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Path Traversal vulnerability that allows an attacker with network access to read any file on the host device. The flaw results from insufficient validation or sanitisation of file path inputs and is classified as a means thereby compromising the confidentiality of the device and potentially the organization relying on it.

Affected Systems

The vulnerability affects Ubiquiti Inc’s UniFi Access Application. No specific version numbers are disclosed, so all installations that have not applied the vendor’s fix remain vulnerable. The flaw impacts devices connected to the same network as the application.

Risk and Exploitability

Based on the description, the likely attack vector is network-based; the attacker must reach the device over the network or an exposed interface. The CVSS score of 8.6. EPSS score is <1%, suggesting a very low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw allows arbitrary file reads, a successful exploit could reveal configuration data, credentials, or logs and thereby compromise confidentiality.

Generated by OpenCVE AI on July 21, 2026 at 11:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the firmware update or patch released by Ubiquiti that addresses the traversal flaw.
  • Restrict network access to the device by using firewall rules or VPN so that only trusted hosts can reach the application.
  • If the application exposes file handling features, enforce strict path validation or disable unnecessary file download options, and keep monitoring Ubiquiti’s security advisories for additional mitigations.

Generated by OpenCVE AI on July 21, 2026 at 11:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Path Traversal in UniFi Access Enables Host File Disclosure

Wed, 15 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Path Traversal in UniFi Access Enables Host File Disclosure

Mon, 13 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Remote File Disclosure via Path Traversal in UniFi Access Application

Sun, 12 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Remote File Disclosure via Path Traversal in UniFi Access Application

Sat, 11 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in UniFi Access Application Allows Unauthorized File Disclosure

Fri, 10 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in UniFi Access Application Allows Unauthorized File Disclosure

Thu, 09 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Path Traversal in Ubiquiti UniFi Access Application Enables Network-Based Information Disclosure

Thu, 09 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Path Traversal in Ubiquiti UniFi Access Application Enables Network-Based Information Disclosure

Wed, 08 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in UniFi Access Application Enabling Information Disclosure

Wed, 08 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in UniFi Access Application Enabling Information Disclosure

Tue, 07 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Unrestricted File Read via Path Traversal in Ubiquiti UniFi Access Application

Mon, 06 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Unrestricted File Read via Path Traversal in Ubiquiti UniFi Access Application

Mon, 06 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Path Traversal in UniFi Access Application Allows File Disclosure

Sun, 05 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Path Traversal in UniFi Access Application Allows File Disclosure

Sun, 05 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Path Traversal in Ubiquiti UniFi Access Application Enables File Disclosure

Sun, 05 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Path Traversal in Ubiquiti UniFi Access Application Enables File Disclosure

Sat, 04 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title UniFi Access Application Path Traversal Vulnerability Enables Host File Disclosure

Sat, 04 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title UniFi Access Application Path Traversal Vulnerability Enables Host File Disclosure

Fri, 03 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Allowing Confidential File Disclosure in UniFi Access Application

Fri, 03 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Path Traversal Allowing Confidential File Disclosure in UniFi Access Application

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Application to access files on the host device.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-02T15:51:41.293Z

Reserved: 2026-06-16T15:00:01.614Z

Link: CVE-2026-55117

cve-icon Vulnrichment

Updated: 2026-07-02T15:49:25.557Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:15:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')