CVE-2026-77553

9.9

Ubiquiti · UniFi Access Application

An improper access control vulnerability in the Ubiquiti UniFi Access Application allows authenticated attackers with low privileges to escalate privileges on the host device.

Executive summary

A critical privilege escalation vulnerability in the Ubiquiti UniFi Access Application poses a severe risk of full system compromise for affected network environments.

Vulnerability

This vulnerability, categorized as CWE-284, involves improper access control within the application that enables a user with low-level network access to elevate their privileges. The attack vector is network-based and requires only low privileges, making it highly dangerous for internal security.

Business impact

The potential for privilege escalation to the host device level carries significant business risk, including complete system takeover and unauthorized access to sensitive network management functions. Given the CVSS score of 9.9, this vulnerability represents an extreme security risk that could facilitate lateral movement, data theft, or prolonged operational disruption.

Remediation

Immediate Action: Update the Ubiquiti UniFi Access Application to version 4.3.5 or higher immediately to resolve the access control flaw.

Proactive Monitoring: Review system access logs for unusual administrative activity or unauthorized attempts to access privileged functions within the UniFi environment.

Compensating Controls: Ensure the application is isolated from untrusted network segments and enforce strict access controls to limit the number of users capable of reaching the management interface.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the critical severity of this vulnerability, immediate patching is required to prevent unauthorized administrative control over the host device. Security teams should prioritize the update to version 4.3.5 across all instances of the UniFi Access Application to eliminate the risk of privilege escalation.

More Ubiquiti CVEs

Sources