VDB
CVE-2026-54400
CVE-2026-54400
PUBLISHED
CVSS 9.1 CRITICAL
Reported by hackerone · Published July 2, 2026
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.
Risk Scores
CVSS 3.1
9.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubiquiti Inc | UniFi Access Application | 0 |
| Ubiquiti Inc | UniFi Access Application | 0 |
Timeline
- Jul 2, 2026 CVE Published
- Jul 2, 2026 CVE Updated
- Jul 3, 2026 EPSS Score
- Jul 4, 2026 Coalition ESS Score