Executive brief
The UniFi Network Application, used to manage Ubiquiti networking hardware, contains a security flaw that allows an authorized user with low-level access to gain higher administrative privileges. If exploited, an attacker could take control of the network management software, potentially leading to unauthorized configuration changes or service disruptions. This risk is particularly relevant for organizations where multiple users have varying levels of access to the management console.
Technical details
An improper access control vulnerability (CWE-284) exists in the Ubiquiti UniFi Network Application. A remote attacker with valid low-privileged credentials can exploit this flaw over the network to escalate their privileges within the application. The vulnerability requires certain unspecified conditions to be met but does not require user interaction. The issue is addressed in UniFi Network Application version 10.4.57 and later.
Affected products
- Ubiquiti Inc UniFi Network Application versions before 10.4.57
Timeline
- 2026-07-02: disclosed
- 2026-07-02: advisory