Description
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device.
Published: 2026-08-26
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in UniFi OS Server allows an attacker with network access and elevated privileges to inject and execute arbitrary commands on the host device. The flaw is caused by improper input validation, making it a classic command injection scenario that can compromise the entire infrastructure managed by the server.

Affected Systems

The affected product is Ubiquiti Inc’s UniFi OS Server. Specific version numbers are not reported in the advisory, so all installations of UniFi OS Server may be vulnerable unless they are already patched to the latest release.

Risk and Exploitability

The CVSS score of 9.1 classifies the issue as critical, reflecting the potential for full system compromise. The EPSS score is unavailable, so the current probability of exploitation is unknown, but the lack of a KEV listing does not diminish the need for rapid remediation. Attacks require the adversary to be on the same network segment and to possess high‑privilege credentials on the server—a condition that many administrators and support staff meet, thereby creating a realistic threat vector.

Generated by OpenCVE AI on August 26, 2026 at 11:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update UniFi OS Server to the latest version that contains the command injection fix.
  • Restrict network traffic to the UniFi OS Server so that only trusted devices and IP ranges can reach it.
  • Enforce strict privilege separation on the UniFi OS Server, limiting administrative access to only the minimum required users.

Generated by OpenCVE AI on August 26, 2026 at 11:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title Command Injection Vulnerability in UniFi OS Server
First Time appeared Ubiquiti
Ubiquiti unifi Os Server
Vendors & Products Ubiquiti
Ubiquiti unifi Os Server

Wed, 26 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ubiquiti Unifi Os Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Ubiquiti

Published:

Updated: 2026-08-26T09:50:36.980Z

Reserved: 2026-08-20T20:32:30.113Z

Link: CVE-2026-77539

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T11:30:05Z

Weaknesses
  • CWE-20

    Improper Input Validation