Impact
UniFi Network Application contains an Improper Access Control flaw (CWE‑284). An attacker who already has low‑privileged network access can use the vulnerability to raise their privileges inside the controller application, potentially moving to an administrative role and gaining full control of the network topology and configuration settings.
Affected Systems
The issue affects Ubiquiti Inc’s UniFi Network Application. No version numbers are specifically mentioned in the advisory, indicating that any installation could be vulnerable until the vendor releases a patch.
Risk and Exploitability
The CVSS score is 8.3, classifying the flaw as high severity. The EPSS score is very low (< 1%) and the vulnerability is not listed in CISA’s KEV catalog, suggesting currently no widespread exploitation. The likely attack path requires the attacker to be inside the network with low‑privileged access and then reach the controller’s web interface; from there the access‑control weakness can be abused to elevate privileges within the application.
OpenCVE Enrichment