CVE-2026-54400: UI UniFi Access
Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.
Affected products
- UI UniFi Access: before 4.2.29 (fixed in 4.2.29)
Published 2026-07-02. Last modified 2026-08-17.