Description
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.
Published: 2026-08-26
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A malicious actor who can reach the network and has low privileges can exploit an improper input validation flaw in UniFi Access Application to run arbitrary system commands on the host device. This allows the attacker to read, modify or delete data, install software, and potentially pivot to other systems in the network. The vulnerability is a classic command injection that compromises confidentiality, integrity and availability of the affected device.

Affected Systems

All installations of Ubiquiti’s UniFi Access Application are vulnerable until an official patch is applied. No specific version information is provided, so the risk applies to every current and legacy release until mitigated.

Risk and Exploitability

The CVSS score of 9.9 indicates a critical risk level, and the vulnerability is not currently listed in CISA’s KEV catalog. The EPSS score is not available, but the lack of listed exploitation suggests no widespread public exploitation yet. Attackers would need to have network access and low privileges; the vulnerability can be triggered remotely over the network once an attacker can interact with the application’s input interfaces.

Generated by OpenCVE AI on August 26, 2026 at 11:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update UniFi Access Application to the latest release from Ubiquiti that contains the input‑validation fix.
  • Restrict access to the application by configuring network segmentation or firewall rules so that only trusted administrative devices can communicate with it.
  • Monitor device logs and network traffic for signs of unexpected command execution or anomalous activity, and investigate any suspicious events promptly.

Generated by OpenCVE AI on August 26, 2026 at 11:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Input Validation in UniFi Access Application

Wed, 26 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Ubiquiti

Published:

Updated: 2026-08-26T10:07:54.505Z

Reserved: 2026-08-20T20:32:37.793Z

Link: CVE-2026-77543

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T11:30:05Z

Weaknesses
  • CWE-20

    Improper Input Validation