Executive brief
Ubiquiti UniFi Access is a door security and building management system. A security flaw in the management application allows an attacker who already has high-level administrative access to the network to further escalate their permissions to the underlying host device. This could lead to full control over the security hardware and the data it manages.
Technical details
An improper access control vulnerability (CWE-284) exists in the Ubiquiti UniFi Access Application prior to version 4.2.29. The flaw allows a network-based attacker with high-level administrative privileges to bypass intended restrictions and escalate their authority to the host operating system level. The vulnerability is characterized by a CVSS 3.1 score of 9.1, notably involving a scope change (S:C), indicating the impact extends beyond the application itself to the underlying infrastructure. Users are advised to update to UniFi Access Application version 4.2.29 or later to mitigate this risk.
Affected products
- Ubiquiti Inc UniFi Access Application < 4.2.29
Timeline
- 2026-07-02: advisory: Security Advisory Bulletin 066 published by Ubiquiti
- 2026-07-02: disclosed: CVE-2026-54400 published to NVD via HackerOne