Junglewise Threat Intelligence

CVE-2026-47367: Ubiquiti UID Enterprise Agent command injection

CVE-2026-47367 · Severity: critical · CVSS 9.9 · Published 2026-06-12

Vendors: Ubiquiti.

Executive brief

A security vulnerability has been identified in the Ubiquiti UID Enterprise Agent, a component used for managing enterprise identity and access. An attacker with low-level network access can take complete control of the host device by injecting unauthorized commands. This could lead to a total compromise of the system, including the theft of sensitive data or disruption of identity management services.

Technical details

The Ubiquiti UID Enterprise Agent is vulnerable to command injection due to improper input validation (CWE-20). An authenticated attacker with low privileges can exploit this flaw over the network by sending specially crafted input that the agent fails to sanitize before execution. Successful exploitation allows for arbitrary command execution on the underlying host operating system with the privileges of the agent. The vulnerability is tracked as CVE-2026-47367 and has been assigned a CVSS v3.1 base score of 9.9, reflecting its high impact on confidentiality, integrity, and availability.

Affected products

  • Ubiquiti UID Enterprise Agent

Timeline

  • 2026-06-12: disclosed
  • 2026-06-12: advisory

References

Related threats