Executive brief
A security vulnerability has been identified in the UniFi Access Application, which manages physical security and door access systems. An attacker with low-level network access can take full control of the host device, potentially leading to a complete system takeover or disruption of physical security operations. This could allow unauthorized individuals to bypass security controls or access sensitive operational data.
Technical details
The UniFi Access Application is vulnerable to command injection due to improper input validation (CWE-20). An attacker authenticated with low privileges can send specially crafted network requests to the application to execute arbitrary system commands on the underlying host. The vulnerability is rated critical (CVSS 9.9) because it allows for a scope change, meaning the attacker can move from the application layer to the host operating system with full confidentiality, integrity, and availability impact. The issue is resolved in UniFi Access Application version 4.2.29 and later.
Affected products
- Ubiquiti Inc UniFi Access Application < 4.2.29
Timeline
- 2026-07-02: disclosed
- 2026-07-02: advisory