Total
4 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-55117 | 1 Ui | 1 Unifi Access | 2026-08-17 | N/A | 8.6 HIGH |
| A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Application to access files on the host device. | |||||
| CVE-2026-54400 | 1 Ui | 1 Unifi Access | 2026-08-17 | N/A | 9.1 CRITICAL |
| A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device. | |||||
| CVE-2026-50748 | 1 Ui | 1 Unifi Access | 2026-08-17 | N/A | 9.9 CRITICAL |
| A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | |||||
| CVE-2025-52665 | 1 Ui | 1 Unifi Access | 2026-06-17 | N/A | 10.0 CRITICAL |
| A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later. Affected Products: UniFi Access Application (Version 3.3.22 through 3.4.31). Mitigation: Update your UniFi Access Application to Version 4.0.21 or later. | |||||
