Description
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.
Published: 2026-08-26
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is caused by Improper Input Validation in UniFi Protect Application, permitting a malicious actor who can reach the device on the local network to inject arbitrary shell commands. Such injection would allow full control of the host, compromising confidentiality, integrity, and availability of the device and potentially any services linked to it.

Affected Systems

All installations of Ubiquiti Inc.'s UniFi Protect Application are potentially affected; the advisory does not specify version ranges. Any device running the Protect application on a network with exposed interfaces can be vulnerable.

Risk and Exploitability

With a CVSS score of 10, the vulnerability is classified as critical. The EPSS score is not provided, so exploitation probability is unknown, but the absence of any published public exploits and lack of a KEV listing suggests the threat is not yet exploited in the wild. The likely attack vector requires network access, meaning devices in unsegmented or poorly protected environments are at higher risk.

Generated by OpenCVE AI on August 26, 2026 at 10:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security patch released by Ubiquiti for UniFi Protect Application as detailed in the vendor advisory.
  • Segregate the Protect device from general network traffic by placing it on a dedicated VLAN or applying strict firewall rules that allow only trusted management interfaces to connect.
  • Enable detailed logging on the Protect device and monitor for anomalous command execution or configuration changes, responding immediately if any suspicious activity is detected.

Generated by OpenCVE AI on August 26, 2026 at 10:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Ubiquiti

Published:

Updated: 2026-08-26T09:39:43.099Z

Reserved: 2026-08-20T20:32:30.112Z

Link: CVE-2026-77537

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T10:30:04Z

Weaknesses
  • CWE-20

    Improper Input Validation