Ubiquiti UniFi Access improper access control (Bulletin 066)
Improper access control in Ubiquiti UniFi Access lets a network attacker with existing high privileges escalate on the host device. CVSS 9.1. Fixed in the patch release accompanying Bulletin 066.
- Vendor
- Ubiquiti
- Product
- UniFi Access
- CVSS
- 9.1
- EPSS (exploit probability)
- 0.5%
- Status
- patched
- Published
CVE-2026-54400 is a CVSS 9.1 critical improper access control in Ubiquiti UniFi Access. Per Security Advisory Bulletin 066, it lets a network attacker with existing high privileges escalate on the host device. It is one of seven critical CVEs disclosed in the same bulletin, headlined by CVE-2026-50746 (CVSS 10.0, command injection in UniFi Connect).
For authoritative affected-version details and patch guidance, see the NVD record and Ubiquiti’s Bulletin 066.
No confirmed exploitation in the wild as of publication. Not on CISA KEV at time of writing.
Full coverage: Ubiquiti Patches Max-Severity UniFi Connect Command Injection.
