Description
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host device.
Published: 2026-08-26
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a flaw in input validation that permits an attacker with network reach and privileged access to inject and execute arbitrary commands on the UID Enterprise Agent host. Such a command injection could lead to complete compromise of the device, granting an attacker full control, data exfiltration, and potential pivot into the broader network. This weakness aligns with CWE‑20.

Affected Systems

The flaw affects Ubiquiti Inc's UID Enterprise Agent. No specific version numbers are disclosed in the advisory, so all installations should be assumed at risk until a vendor patch is applied.

Risk and Exploitability

The CVSS score of 9.1 classifies the issue as Critical, and while EPSS data is unavailable, the lack of mitigation in the KEV suggests it has not yet been widely exploited publicly. The attack vector is inferred to be network‑based with high privileges, meaning attackers with local network presence or compromised credentials can exploit it. The absence of a public exploit does not diminish the potential damage if accessed internally.

Generated by OpenCVE AI on August 26, 2026 at 11:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware or software update for UID Enterprise Agent from Ubiquiti.
  • Restrict network access to the management interfaces of the device, using firewalls and access control lists to allow only trusted IP ranges.
  • Enforce least privilege for any accounts that can access the device and consider disabling or limiting remote management features if they are unnecessary.

Generated by OpenCVE AI on August 26, 2026 at 11:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title UID Enterprise Agent Improper Input Validation Leading to Command Injection

Wed, 26 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host device.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Ubiquiti

Published:

Updated: 2026-08-26T10:01:39.351Z

Reserved: 2026-08-20T20:32:30.113Z

Link: CVE-2026-77542

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T11:30:05Z

Weaknesses
  • CWE-20

    Improper Input Validation