Description
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.
Published: 2026-08-26
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Command Injection
Action: Apply Patch
AI Analysis

Impact

An improperly validated input field in the UniFi Access Application permits a low‑privilege attacker with network access to inject arbitrary shell commands onto the host device, potentially compromising confidentiality, integrity, and availability. The vulnerability maps to CWE‑20 — Input Validation. Because the injection runs directly on the host, a successful exploitation could lead to unrestricted command execution with the privileges of the application process, allowing a broad range of post‑exploitation actions.

Affected Systems

The weakness exists in Ubiquiti Inc’s UniFi Access Application. All releases of the application are affected, as specific version details are not provided in the advisory.

Risk and Exploitability

The CVSS base score of 9.9 places the flaw in the Critical range, indicating a high likelihood of severe impact. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog at this time. Attackers would need unauthenticated or low‑privileged network access to the UniFi Access Application; the vulnerability can be leveraged by sending crafted input that bypasses normal validation to inject shell commands, executing them on the host system.

Generated by OpenCVE AI on August 26, 2026 at 11:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest fix or update for UniFi Access Application as released by Ubiquiti.
  • Restrict network access to the UniFi Access Application by limiting traffic to trusted internal segments or approved IP addresses.
  • Remove or limit low‑privilege user accounts that can interact with or access the UniFi Access Application.

Generated by OpenCVE AI on August 26, 2026 at 11:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Ui
Ui unifi Access Application
Vendors & Products Ui
Ui unifi Access Application

Wed, 26 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Title Command Injection Vulnerability in Ubiquiti UniFi Access Application

Wed, 26 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ui Unifi Access Application
cve-icon MITRE

Status: PUBLISHED

Assigner: Ubiquiti

Published:

Updated: 2026-08-26T13:19:37.445Z

Reserved: 2026-08-20T20:32:37.793Z

Link: CVE-2026-77546

cve-icon Vulnrichment

Updated: 2026-08-26T13:19:34.416Z

cve-icon NVD

Status : Deferred

Published: 2026-08-26T11:16:38.463

Modified: 2026-08-28T18:49:15.340

Link: CVE-2026-77546

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:24:18Z

Weaknesses
  • CWE-20

    Improper Input Validation