Executive brief
UniFi Access is Ubiquiti's access control and management application used to secure physical and network access to enterprise facilities. A network-accessible command injection vulnerability allows attackers with low privileges to execute arbitrary system commands on the access control hardware, potentially compromising the entire access control infrastructure and enabling unauthorized physical access.
Technical details
UniFi Access contains an improper input validation flaw that enables command injection attacks. An attacker with network access and low-level privileges can craft malicious input that bypasses validation checks and execute arbitrary commands with system-level privileges on the host device. The vulnerability requires network access but no authentication escalation, making it exploitable by low-privilege users already on the network. Successful exploitation allows complete compromise of the access control system, including credential theft, access policy modification, and facility access bypasses.
Affected products
- Ubiquiti UniFi Access
Timeline
- 2026-08-26: disclosed