Impact
The vulnerability is an Improper Access Control flaw in the UniFi Network Application that allows an attacker with network access and elevated privileges to gain elevated privileges inside the application. An attacker can exploit this to perform unauthorized actions, potentially controlling devices, modifying settings, or accessing sensitive information.
Affected Systems
Affected systems include the Ubiquiti UniFi Network Application; specific affected versions are not specified in the advisory.
Risk and Exploitability
The flaw is rated with a CVSS score of 9.1, indicating critical severity. EPSS information is unavailable, and the vulnerability is not yet listed in the CISA KEV catalogue. An attacker must be able to reach the UniFi controller over the network and possess or obtain high‑privilege access. The attack may proceed by exploiting improper access checks in the application, enabling the attacker to elevate privileges without additional user interaction.
OpenCVE Enrichment