Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-77553: UniFi Access app lets low‑privilege network user gain admin rights
CVE-2026-77553 · published 8 days ago
Summary
The UniFi Access software on your network can be tricked by someone with only basic access to take control of the whole system. This means a user with limited rights could become an administrator and manipulate the device. Apply the latest update from the vendor as soon as possible to close the gap.
What to do
- Update ubiquiti inc unifi access application to version 4.3.5 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ubiquiti inc | unifi access application | < 4.3.5 |
Original advisory text
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.
Severity
9.9
Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-284Improper Access Control
Timeline
Published26 Aug 2026
Updated28 Aug 2026
First seen26 Aug 2026
Monitor software like this
Free during beta