Description
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Command Injection on an adopted device.
Published: 2026-08-26
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in input validation within the UniFi Network Application permits a malicious actor who has network access and high privileges to inject and execute arbitrary commands on a device that has been adopted by the controller. The vulnerability enables remote command injection, allowing the attacker to run code with the privileges of the targeted device.

Affected Systems

All installations of Ubiquiti’s UniFi Network Application that have adopted devices are potentially vulnerable. No specific product version is identified, so any deployed instance may be affected until a patch or update is applied.

Risk and Exploitability

The CVSS score of 9.1 indicates a very high severity issue. EPSS data is not available and the vulnerability is not listed in CISA's KEV catalog, implying no known widespread exploitation yet. However, the required conditions—network access and elevated privileges—are common in many managed network environments, making the risk high and warranting immediate attention.

Generated by OpenCVE AI on August 26, 2026 at 10:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware or software update released by Ubiquiti for the UniFi Network Application to address the input validation flaw.
  • Restrict network access to the UniFi controller by placing it on a trusted subnet and limiting administrative traffic to known devices and IP addresses.
  • Enable detailed logging on the controller and monitor for unexpected command execution attempts to detect possible exploitation.

Generated by OpenCVE AI on August 26, 2026 at 10:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Input Validation in UniFi Network Application
First Time appeared Ubiquiti
Ubiquiti unifi Network Application
Vendors & Products Ubiquiti
Ubiquiti unifi Network Application

Wed, 26 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Command Injection on an adopted device.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ubiquiti Unifi Network Application
cve-icon MITRE

Status: PUBLISHED

Assigner: Ubiquiti

Published:

Updated: 2026-08-26T09:27:25.053Z

Reserved: 2026-08-20T20:32:30.112Z

Link: CVE-2026-77535

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T11:00:05Z

Weaknesses
  • CWE-20

    Improper Input Validation