← Back

Unifi Access

unifi_access

Vendor: Ui • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ui
2Unifi Access
Unifi Access Application
Aug 17, 2026
Jul 2, 2026
N/A· v4
8.6 HIGH· v3
N/A· v2
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Application to access files on the host device.
1Ui
2Unifi Access
Unifi Access Application
Aug 17, 2026
Jul 2, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.
1Ui
2Unifi Access
Unifi Access Application
Aug 17, 2026
Jul 2, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.
1Ui
1Unifi Access
Jun 17, 2026
Oct 31, 2025
N/A· v4
10.0 CRITICAL· v3
N/A· v2
A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability w...Show more
A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later.  Affected Products: UniFi Access Application (Version 3.3.22 through 3.4.31). 
 Mitigation: Update your UniFi Access Application to Version 4.0.21 or later.Show less