Description
A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Network Application to persist privileges within UniFi Network Application after such access had been removed.
Published: 2026-07-02
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A malicious actor with network access can exploit an incorrect authorization flaw in the UniFi Network Application to maintain elevated privileges in the controller even after the original access has been revoked. The vulnerability is catalogued as CWE‑863, indicating improper enforcement of authorization controls and potentially allowing an attacker to persist unauthorized rights indefinitely.

Affected Systems

Ubiquiti Inc’s UniFi Network Application is affected. No specific vulnerable versions are provided in the advisory, so the risk applies to any deployment of the application until a vendor patch is released.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, but the EPSS score of less than 1% highlights a low likelihood of exploitation. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that an attacker would need network access that permits interaction with the controller after an initial compromise. In the absence of an official workaround, risk mitigation focuses on restricting the controller’s exposure and applying a future vendor‑issued patch.

Generated by OpenCVE AI on July 21, 2026 at 11:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available vendor patch for UniFi Network Application as soon as it is released.
  • Restrict access to the UniFi controller by limiting connections to trusted management IP ranges and enforce strict certificate authentication.
  • Place the controller on a dedicated, isolated management network segment and enforce network segmentation to prevent cross‑traffic from untrusted devices.

Generated by OpenCVE AI on July 21, 2026 at 11:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization Allows Persistent Privileges in UniFi Network Application

Thu, 16 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Privilege Persistence Exploitation in UniFi Network Application via Incorrect Authorization

Tue, 14 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Privilege Persistence Exploitation in UniFi Network Application via Incorrect Authorization

Sun, 12 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Privilege Persistence via Incorrect Authorization in UniFi Network Application

Sat, 11 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Privilege Persistence via Incorrect Authorization in UniFi Network Application

Fri, 10 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Persistent Privilege Exploitation Due to Incorrect Authorization in UniFi Network Application

Thu, 09 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Persistent Privilege Exploitation Due to Incorrect Authorization in UniFi Network Application

Wed, 08 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Privilege Persistence in UniFi Network Application via Incorrect Authorization

Tue, 07 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Privilege Persistence in UniFi Network Application via Incorrect Authorization

Mon, 06 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Privilege Persistence via Incorrect Authorization in UniFi Network Application

Mon, 06 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Privilege Persistence via Incorrect Authorization in UniFi Network Application

Mon, 06 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Privilege Persistence via Incorrect Authorization in Ubiquiti UniFi Network Application

Sun, 05 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Privilege Persistence via Incorrect Authorization in Ubiquiti UniFi Network Application

Sun, 05 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization in UniFi Network Application Enables Privilege Persistence

Sun, 05 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization in UniFi Network Application Enables Privilege Persistence

Sat, 04 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Privilege Persistence via Incorrect Authorization in UniFi Network Application

Sat, 04 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Privilege Persistence via Incorrect Authorization in UniFi Network Application

Sat, 04 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Privilege Persistence via Incorrect Authorization in UniFi Network Application

Fri, 03 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Privilege Persistence via Incorrect Authorization in UniFi Network Application

Fri, 03 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization in UniFi Network Application Allows Persistent Privileges

Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization in UniFi Network Application Allows Persistent Privileges

Thu, 02 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Ubiquiti
Ubiquiti unifi Network Application
Vendors & Products Ubiquiti
Ubiquiti unifi Network Application

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Network Application to persist privileges within UniFi Network Application after such access had been removed.
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ubiquiti Unifi Network Application
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-02T15:50:57.619Z

Reserved: 2026-06-23T15:00:03.632Z

Link: CVE-2026-56842

cve-icon Vulnrichment

Updated: 2026-07-02T15:41:20.554Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:15:05Z

Weaknesses