Description
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.
Published: 2026-08-26
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Improper Access Control flaw in the UniFi Network Application that allows an attacker with network access and elevated privileges to gain elevated privileges inside the application. An attacker can exploit this to perform unauthorized actions, potentially controlling devices, modifying settings, or accessing sensitive information.

Affected Systems

Affected systems include the Ubiquiti UniFi Network Application; specific affected versions are not specified in the advisory.

Risk and Exploitability

The flaw is rated with a CVSS score of 9.1, indicating critical severity. EPSS information is unavailable, and the vulnerability is not yet listed in the CISA KEV catalogue. An attacker must be able to reach the UniFi controller over the network and possess or obtain high‑privilege access. The attack may proceed by exploiting improper access checks in the application, enabling the attacker to elevate privileges without additional user interaction.

Generated by OpenCVE AI on August 26, 2026 at 12:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review Ubiquiti's Security Advisory and assess whether a patch or update is available.
  • Restrict network access to the UniFi controller by limiting connections to trusted IP ranges and closing unnecessary ports.
  • Implement least‑privilege role definitions and enable two‑factor authentication for all administrative accounts.

Generated by OpenCVE AI on August 26, 2026 at 12:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in Ubiquiti UniFi Network Application

Wed, 26 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Ubiquiti

Published:

Updated: 2026-08-26T13:23:20.467Z

Reserved: 2026-08-20T20:32:30.113Z

Link: CVE-2026-77541

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T12:30:05Z

Weaknesses