Executive brief
Ubiquiti UniFi Access Application, a software suite used to manage physical security and door access systems, contains a vulnerability that allows unauthorized network users to access sensitive files. An attacker could exploit this to read system configuration files or other data stored on the host device. This could lead to the exposure of credentials or other information necessary to compromise the physical security infrastructure.
Technical details
A path traversal vulnerability (CWE-22) exists in the Ubiquiti UniFi Access Application prior to version 4.2.29. The flaw allows an unauthenticated attacker with network access to the application to bypass directory restrictions and read arbitrary files on the underlying host operating system. The vulnerability is characterized by a CVSS 3.1 score of 8.6, reflecting high confidentiality impact and a changed scope, as the exploit allows access to files outside of the application's intended web root. Users are advised to update to version 4.2.29 or later to mitigate this risk.
Affected products
- Ubiquiti Inc UniFi Access Application < 4.2.29
Timeline
- 2026-07-02: advisory: Initial publication of CVE-2026-55117 and vendor bulletin 066.
- 2026-07-02: patched: Vulnerability addressed in UniFi Access Application version 4.2.29.