Description
A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.
Published: 2026-07-02
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

UniFi Network Application contains an Improper Access Control flaw (CWE‑284). An attacker who already has low‑privileged network access can use the vulnerability to raise their privileges inside the controller application, potentially moving to an administrative role and gaining full control of the network topology and configuration settings.

Affected Systems

The issue affects Ubiquiti Inc’s UniFi Network Application. No version numbers are specifically mentioned in the advisory, indicating that any installation could be vulnerable until the vendor releases a patch.

Risk and Exploitability

The CVSS score is 8.3, classifying the flaw as high severity. The EPSS score is very low (< 1%) and the vulnerability is not listed in CISA’s KEV catalog, suggesting currently no widespread exploitation. The likely attack path requires the attacker to be inside the network with low‑privileged access and then reach the controller’s web interface; from there the access‑control weakness can be abused to elevate privileges within the application.

Generated by OpenCVE AI on July 21, 2026 at 11:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest UniFi Network Application firmware that includes the access‑control fix, as outlined in Ubiquiti’s security bulletin
  • Restrict the controller’s management interface to a dedicated VLAN or IP whitelist to limit reach to trusted administrators
  • Enforce strong, multi‑factor authentication and conduct regular privilege reviews to prevent unnecessary high‑privilege assignments

Generated by OpenCVE AI on July 21, 2026 at 11:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in UniFi Network Application via Improper Access Control

Wed, 15 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Network Application

Sun, 12 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Network Application

Sat, 11 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in Ubiquiti UniFi Network Application

Fri, 10 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in Ubiquiti UniFi Network Application

Thu, 09 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Network Application

Wed, 08 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Network Application

Wed, 08 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Network Application

Tue, 07 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Network Application

Mon, 06 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Network Application

Mon, 06 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Network Application

Sun, 05 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control Enables Privilege Escalation in Ubiquiti UniFi Network Application

Sun, 05 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control Enables Privilege Escalation in Ubiquiti UniFi Network Application

Sun, 05 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Network Application Enables Privilege Escalation

Sat, 04 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Network Application Enables Privilege Escalation

Sat, 04 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control Allows Escalation of Privileges in UniFi Network Application

Sat, 04 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control Allows Escalation of Privileges in UniFi Network Application

Fri, 03 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in UniFi Network Application via Improper Access Control

Fri, 03 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in UniFi Network Application via Improper Access Control

Thu, 02 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Ubiquiti
Ubiquiti unifi Network Application
Vendors & Products Ubiquiti
Ubiquiti unifi Network Application

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H'}


Subscriptions

Ubiquiti Unifi Network Application
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-02T15:51:29.494Z

Reserved: 2026-06-16T15:00:01.614Z

Link: CVE-2026-55118

cve-icon Vulnrichment

Updated: 2026-07-02T15:48:44.375Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:15:05Z

Weaknesses