CVE-2026-56842

HIGH

Ubiquiti INC UniFi Network Application < 10.4.57 - Incorrect Authorization

Title source: rule
STIX 2.1

Description

A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Network Application to persist privileges within UniFi Network Application after such access had been removed.

Scores

CVSS v3 7.5
EPSS 0.0019
EPSS Percentile 8.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (1)
Ubiquiti Inc/UniFi Network Application < 10.4.57
Published Jul 02, 2026
Tracked Since Jul 02, 2026