Description
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.
Published: 2026-08-26
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An Improper Input Validation flaw in the UniFi Protect Application allows an attacker who has network access and only low privileges on the host to inject and execute arbitrary system commands. The vulnerability can result in full control of the device, enabling the attacker to exfiltrate data, deploy malware, or pivot to other hosts on the network, compromising confidentiality, integrity, and availability of the protected video surveillance infrastructure.

Affected Systems

The flaw affects Ubiquiti Inc's UniFi Protect Application. The CVE report does not specify particular versions, so any deployment of this application that has not been patched by the vendor is potentially susceptible.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.9, indicating critical severity. Although the EPSS score is not available, the lack of a KEV listing does not diminish the inherent risk posed by the high CVSS. Attackers would need only local network connectivity and basic user privileges, which are commonly available on many deploy environments. Given the high CVSS, the potential for exploitation is high, and organizations should treat this as a top‑priority risk.

Generated by OpenCVE AI on August 26, 2026 at 10:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch for UniFi Protect to eliminate the input validation flaw
  • Configure network segmentation to restrict access to the UniFi Protect device to trusted administrators only
  • Disable or limit any HTTP API endpoints that allow remote execution of system commands
  • Review and harden the device’s logging configuration to capture suspicious command execution attempts

Generated by OpenCVE AI on August 26, 2026 at 10:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Title Improper Input Validation Enables Remote Command Injection on UniFi Protect

Wed, 26 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Ubiquiti

Published:

Updated: 2026-08-26T08:57:33.271Z

Reserved: 2026-08-20T20:32:30.112Z

Link: CVE-2026-77533

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T10:30:04Z

Weaknesses
  • CWE-20

    Improper Input Validation