Description
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Enterprise Audio/Video Bridge to execute a Command Injection on the device.
Published: 2026-08-26
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerable input validation flaw in UniFi Enterprise Audio/Video Bridge allows an attacker to inject arbitrary shell commands. The flaw is a classic example of CWE-20, leading to untrusted data being passed to the operating system without proper sanitization. If an attacker succeeds, they can execute any command with the privileges of the bridge process, compromising device integrity and potentially the entire local network.

Affected Systems

The vulnerability affects Ubiquiti Inc’s UniFi Enterprise Audio/Video Bridge hardware. No specific firmware or version information is disclosed, so any device model using the affected Bridge firmware and exposed to the local network is potentially impacted. The device typically operates behind local routers but is reachable by any host on the internal network that can reach the bridge IP address.

Risk and Exploitability

The assigned CVSS score is 9.8, indicating a critical severity. EPSS data is not available, so the current likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog, but its critical SCORE and the required network access suggest that a determined attacker with local network privileges could easily abuse it. The likely attack vector is a local network attack, requiring an attacker to be on the same segment as the bridge.

Generated by OpenCVE AI on August 26, 2026 at 12:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor-provided firmware update for UniFi Enterprise Audio/Video Bridge as soon as it becomes available.
  • Restrict physical and logical access to the bridge device by segmenting it into a separate VLAN or subnet and limiting exposure to trusted hosts only.
  • Disable or block all unused management ports and interfaces to reduce the attack surface, ensuring that only authenticated and authorized administrators can reach the device’s management interface.

Generated by OpenCVE AI on August 26, 2026 at 12:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Input Validation in UniFi Enterprise Audio/Video Bridge

Wed, 26 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Enterprise Audio/Video Bridge to execute a Command Injection on the device.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Ubiquiti

Published:

Updated: 2026-08-26T12:46:01.853Z

Reserved: 2026-08-20T20:32:37.794Z

Link: CVE-2026-77552

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T12:30:05Z

Weaknesses
  • CWE-20

    Improper Input Validation