Ubiquiti UniFi Access Management API Authentication Bypass Vulnerability

Vulnerability

A vulnerability exists in the Ubiquiti UniFi Access application, specifically in versions 3.3.22 through 3.4.31. A misconfiguration has exposed a management API on the door access application, allowing unauthorized access to the API by malicious actors on the management network. This vulnerability could be exploited to manipulate access control features or disrupt service.

Impact

Exploitation of this vulnerability could lead to unauthorized access to the management API, allowing for potential manipulation of access control features or disruption of service.

Remediation

Users are advised to update the UniFi Access application to version 4.0.21 or later.

Added: Oct 31, 2025, 12:27 AM
Updated: Oct 31, 2025, 12:27 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.0
exploitability
4.9
remediation
7.7
relevance
0.8
threat
0.5
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.