CVE-2026-77541
Ubiquiti UniFi vulnerability analysis and mitigation

Overview

CVE-2026-77541 is an Improper Access Control vulnerability in Ubiquiti's UniFi Network Application that allows a high-privileged, network-authenticated attacker to escalate privileges within the application. It affects all versions of UniFi Network Application prior to 10.5.67, as assigned by Ubiquiti Inc. The vulnerability was published on August 26, 2026, and carries a CVSS v3.1 base score of 9.1 (Critical) (Ubiquiti Advisory, ENISA EUVD).

Technical details

The vulnerability is classified as CWE-284 (Improper Access Control), meaning the application fails to properly enforce access restrictions on privileged operations or resources within the UniFi Network Application. An attacker who already holds high-level privileges and has network access to the application can exploit this flaw to further escalate their privileges, potentially gaining full administrative control. The changed scope (S:C) in the CVSS vector indicates that the impact extends beyond the vulnerable component itself. No public technical write-ups or proof-of-concept code have been identified at this time (Ubiquiti Advisory, ENISA EUVD).

Impact

Successful exploitation grants a high-privileged attacker elevated administrative control over the UniFi Network Application, with high impact to confidentiality, integrity, and availability. Because the CVSS scope is marked as Changed, the consequences can extend beyond the application itself to underlying network infrastructure managed by UniFi, potentially enabling unauthorized configuration changes, data exfiltration, or disruption of managed network devices. This makes the vulnerability particularly dangerous in enterprise or campus network environments where UniFi manages critical infrastructure (Ubiquiti Advisory, GBHackers).

Exploitability

There is currently no public proof-of-concept exploit and no confirmed in-the-wild exploitation of CVE-2026-77541. The EPSS score is approximately 0.257%, reflecting a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an attacker to already possess high privileges and network access to the UniFi Network Application, which limits the attack surface compared to unauthenticated vulnerabilities (ENISA EUVD, Ubiquiti Advisory).

Mitigation and workarounds

Ubiquiti has addressed this vulnerability in UniFi Network Application version 10.5.67 and later; administrators should upgrade immediately. As interim mitigations, restrict network access to the UniFi Network Application to trusted administrators only, implement network segmentation to limit which users can reach the management interface, and enforce strict privilege management to minimize the number of high-privileged accounts. Monitor administrative activity logs for unexpected privilege changes or unusual administrative actions (Ubiquiti Advisory, ENISA EUVD).

Community reactions

Ubiquiti disclosed this vulnerability as part of Security Advisory Bulletin 067, which addressed 22 UniFi flaws in total, including three with maximum CVSS scores (Ubiquiti Advisory). Security news outlets including GBHackers, CyberSecurityNews, and TechTimes covered the broader advisory, highlighting the scale of the patch release and the presence of critical-severity flaws across the UniFi ecosystem (GBHackers, CyberSecurityNews, TechTimes). Community reaction focused on the breadth of the advisory rather than this specific CVE, with no notable individual researcher commentary identified.

Additional resources


SourceThis report was generated using AI

Related Ubiquiti UniFi vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77541CRITICAL9.1
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesAug 26, 2026
CVE-2026-77535CRITICAL9.1
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesAug 26, 2026
CVE-2026-55114HIGH8.8
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesJul 02, 2026
CVE-2026-55118HIGH8.3
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesJul 02, 2026
CVE-2026-56842HIGH7.5
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesJul 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management