Description
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to escalate privileges within the UniFi Connect Application.
Published: 2026-08-26
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper access control flaw that allows a malicious actor with network access to elevate privileges within the UniFi Connect Application. By gaining higher privileges, an attacker could alter application settings, configure network devices, and potentially bypass other security controls, thereby compromising the confidentiality, integrity, and availability of the managed network. The weakness maps to CWE-284, indicating a failure to enforce adequate access restrictions.

Affected Systems

Affected systems are devices running Ubiquiti’s UniFi Connect Application. No specific version details are provided, so all current releases are likely vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 8.2 signals a high severity risk, and while the EPSS score is not available, the lack of listing in CISA’s KEV catalog suggests no publicly available exploits are known yet. The likely attack vector is a network-based attacker who can reach the application’s ports; successful exploitation requires network proximity and the ability to authenticate locally or via default credentials. If exploited, the attacker could effectively operate with privileged application-level access.

Generated by OpenCVE AI on August 26, 2026 at 11:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest UniFi Connect version that includes the access control fix
  • Restrict network access to the UniFi Connect Application by limiting inbound traffic to trusted management IP ranges
  • Configure and monitor application logs for anomalous privilege escalation attempts

Generated by OpenCVE AI on August 26, 2026 at 11:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in UniFi Connect Application

Wed, 26 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to escalate privileges within the UniFi Connect Application.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Ubiquiti

Published:

Updated: 2026-08-26T12:55:09.691Z

Reserved: 2026-08-20T20:32:30.113Z

Link: CVE-2026-77538

cve-icon Vulnrichment

Updated: 2026-08-26T12:55:05.315Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T12:00:05Z

Weaknesses