Description
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.
Published: 2026-08-26
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Command Injection
Action: Patch Immediately
AI Analysis

Impact

The UniFi Protect Application contains an improper input validation flaw that allows a network actor with low privileges to inject arbitrary commands into the host system. By sending specially crafted input, an attacker can trigger command execution on the device, compromising the confidentiality, integrity, and availability of the system. This represents a classic command injection vulnerability (CWE‑20).

Affected Systems

All versions of Ubiquiti Inc's UniFi Protect Application that do not contain the vendor’s recent patch are affected. No specific version numbers are disclosed in the advisory, so administrators should assume all existing deployments are vulnerable until a fix is applied.

Risk and Exploitability

The severity is CVSS 9.9, indicating a critical risk. Although the EPSS score is not available and the vulnerability is not listed in CISA KEV, the requirement for only network access and low privileges means that internal attackers can easily exploit it. The resulting command injection grants full control over the host device, making this a high‑impact, high‑likelihood threat if left unmitigated.

Generated by OpenCVE AI on August 26, 2026 at 11:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or upgrade to the newest version of UniFi Protect that addresses the input validation flaw.
  • Restrict network access to the UniFi Protect device by enabling role‑based access controls or firewall rules that limit traffic to trusted IP ranges.
  • Disable or remove any unnecessary remote services or interfaces that could be exploited for command injection, and follow best practices for input sanitization to mitigate similar vulnerabilities in the future.
  • If a patch is not yet available, isolate the device from the internal network and enforce the principle of least privilege for users accessing the system.

Generated by OpenCVE AI on August 26, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Ubiquiti
Ubiquiti protect Application
Vendors & Products Ubiquiti
Ubiquiti protect Application

Wed, 26 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Input Validation in Ubiquiti UniFi Protect

Wed, 26 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ubiquiti Protect Application
cve-icon MITRE

Status: PUBLISHED

Assigner: Ubiquiti

Published:

Updated: 2026-08-26T12:51:38.840Z

Reserved: 2026-08-20T20:32:37.794Z

Link: CVE-2026-77548

cve-icon Vulnrichment

Updated: 2026-08-26T12:51:35.386Z

cve-icon NVD

Status : Deferred

Published: 2026-08-26T11:16:38.693

Modified: 2026-08-28T18:49:15.340

Link: CVE-2026-77548

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:24:14Z

Weaknesses
  • CWE-20

    Improper Input Validation