Description
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device.
Published: 2026-08-26
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via Command Injection
Action: Immediate Patch
AI Analysis

Impact

A flaw that allows a malicious actor with access to the internal network and elevated privileges to inject arbitrary commands into the UniFi OS Server. The vulnerability is an improper validation of input that leads to command injection on the host device, effectively granting full control over the system. Such an execution path can compromise data confidentiality, integrity, and availability, and can be leveraged to propagate to other network assets.

Affected Systems

The affected product is the UniFi OS Server from Ubiquiti Inc. No specific version information is listed, so any installation of the server that has not been updated to the latest firmware may be vulnerable.

Risk and Exploitability

The CVSS score of 9.1 classifies this issue as Critical. The EPSS score is not available, but the vulnerability is not listed in CISA’s KEV catalog. A likely attack vector requires the attacker to be on the same internal network and to possess high-level privileges on the device or the ability to send crafted input to the server’s interfaces. Once exploited, the attacker could execute arbitrary commands with the privileges of the UniFi OS Server process.

Generated by OpenCVE AI on August 26, 2026 at 12:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor-released updates or patches for UniFi OS Server that address the input validation flaw.
  • Restrict management interface access to authorized administrators only and enforce strong authentication for any remote connections.
  • Implement network segmentation and firewall rules that limit traffic to the UniFi OS Server from untrusted sources and monitor logs for abnormal command execution attempts.

Generated by OpenCVE AI on August 26, 2026 at 12:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Input Validation in UniFi OS Server

Wed, 26 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Ubiquiti
Ubiquiti unifi Os Server
Vendors & Products Ubiquiti
Ubiquiti unifi Os Server

Wed, 26 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ubiquiti Unifi Os Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Ubiquiti

Published:

Updated: 2026-08-27T03:56:53.322Z

Reserved: 2026-08-20T20:32:30.113Z

Link: CVE-2026-77540

cve-icon Vulnrichment

Updated: 2026-08-26T13:31:36.854Z

cve-icon NVD

Status : Deferred

Published: 2026-08-26T10:16:41.920

Modified: 2026-08-28T18:49:15.340

Link: CVE-2026-77540

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T12:30:05Z

Weaknesses
  • CWE-20

    Improper Input Validation