Description
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.
Published: 2026-08-26
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch
AI Analysis

Impact

A malicious actor with access to the network and low privileges can exploit an improper access control flaw in the UniFi Access Application to elevate privileges on the host device. The vulnerability is rated with a CVSS score of 9.9, indicating a critical impact on confidentiality, integrity, and availability for affected systems.

Affected Systems

The vulnerability affects Ubiquiti Inc.’s UniFi Access Application. Specific affected versions are not listed in the available data.

Risk and Exploitability

The CVSS score of 9.9 categorizes this flaw as critical, and although the EPSS score is not available, the absence of a KEV listing suggests that it has not yet been widely exploited. The review indicates that a local network presence and low privileges are sufficient prerequisites, implying that an attacker could target any device on the same network segment. Given its severity and the potential for local privilege escalation, the risk remains high until a patch is applied.

Generated by OpenCVE AI on August 26, 2026 at 12:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the UniFi Access Application to the latest official version when it becomes available.
  • Restrict network access to the UniFi Access Application so that only trusted devices or authenticated users can reach it.
  • Monitor access logs and network traffic for anomalous activity that might indicate exploitation attempts.

Generated by OpenCVE AI on August 26, 2026 at 12:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Ui
Ui unifi Access Application
Vendors & Products Ui
Ui unifi Access Application

Wed, 26 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Access Application Enables Privilege Escalation

Wed, 26 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ui Unifi Access Application
cve-icon MITRE

Status: PUBLISHED

Assigner: Ubiquiti

Published:

Updated: 2026-08-26T12:45:32.606Z

Reserved: 2026-08-20T20:32:43.655Z

Link: CVE-2026-77553

cve-icon Vulnrichment

Updated: 2026-08-26T12:45:29.308Z

cve-icon NVD

Status : Deferred

Published: 2026-08-26T11:16:39.283

Modified: 2026-08-28T18:49:15.340

Link: CVE-2026-77553

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:24:12Z

Weaknesses