Junglewise Threat Intelligence

CVE-2026-56842: Ubiquiti UniFi Network Application incorrect authorization

CVE-2026-56842 · Severity: high · CVSS 7.5 · Published 2026-07-02

Technologies: Ubiquiti UniFi Network Application. Vendors: Ubiquiti, Ubiquiti Inc.

Executive brief

Ubiquiti UniFi Network Application, which is used to manage and configure network devices, contains a security flaw that allows a user to maintain their access even after it should have been revoked. An attacker who already has low-level access to the network could exploit this to keep their administrative or elevated privileges indefinitely. This could lead to unauthorized changes to network settings or long-term monitoring of network traffic.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the Ubiquiti UniFi Network Application prior to version 10.4.57. The flaw allows an authenticated user with low privileges to persist their access or elevated permissions even after an administrator has attempted to remove or downgrade those permissions. The attack requires network access and occurs under specific conditions (High Attack Complexity), but it allows for a complete compromise of confidentiality, integrity, and availability within the application context. Users are advised to update to version 10.4.57 or later to remediate the issue.

Affected products

  • Ubiquiti Inc UniFi Network Application < 10.4.57

Timeline

  • 2026-07-02: disclosed
  • 2026-07-02: advisory

References

Related threats