Description
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.
Published: 2026-08-26
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The UniFi Protect Application contains an improper input validation flaw that allows a network actor with low privileges to inject arbitrary commands into the host system. By sending specially crafted input, an attacker can trigger command execution on the device, compromising the confidentiality, integrity, and availability of the system. This represents a classic command injection vulnerability (CWE‑20).

Affected Systems

All versions of Ubiquiti Inc's UniFi Protect Application that do not contain the vendor’s recent patch are affected. No specific version numbers are disclosed in the advisory, so administrators should assume all existing deployments are vulnerable until a fix is applied.

Risk and Exploitability

The severity is CVSS 9.9, indicating a critical risk. Although the EPSS score is not available and the vulnerability is not listed in CISA KEV, the requirement for only network access and low privileges means that internal attackers can easily exploit it. The resulting command injection grants full control over the host device, making this a high‑impact, high‑likelihood threat if left unmitigated.

Generated by OpenCVE AI on August 26, 2026 at 11:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or upgrade to the newest version of UniFi Protect that addresses the input validation flaw.
  • Restrict network access to the UniFi Protect device by enabling role‑based access controls or firewall rules that limit traffic to trusted IP ranges.
  • Disable or remove any unnecessary remote services or interfaces that could be exploited for command injection, and follow best practices for input sanitization to mitigate similar vulnerabilities in the future.
  • If a patch is not yet available, isolate the device from the internal network and enforce the principle of least privilege for users accessing the system.

Generated by OpenCVE AI on August 26, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Input Validation in Ubiquiti UniFi Protect

Wed, 26 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Ubiquiti

Published:

Updated: 2026-08-26T10:23:37.645Z

Reserved: 2026-08-20T20:32:37.794Z

Link: CVE-2026-77548

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T11:30:05Z

Weaknesses
  • CWE-20

    Improper Input Validation