Junglewise Threat Intelligence

CVE-2026-77533: Ubiquiti UniFi Protect command injection via improper input validation

CVE-2026-77533 · Severity: critical · CVSS 9.9 · Published 2026-08-26

Technologies: Ubiquiti UniFi Protect. Vendors: Ubiquiti.

Executive brief

UniFi Protect is a surveillance and access control management application used by organizations to monitor and secure physical premises. An attacker with network access and low privileges could inject malicious commands through improperly validated input, gaining the ability to execute arbitrary code on the host device and potentially compromise the entire security infrastructure.

Technical details

A command injection vulnerability exists in UniFi Protect Application due to improper input validation. An attacker with network access and low-level privileges can craft malicious input that bypasses validation controls and is passed unsanitized to command execution functions on the host device. This allows remote code execution (RCE) with the privileges of the application, potentially leading to full system compromise. The vulnerability is classified as critical with a CVSS score of 9.9, indicating severe impact across confidentiality, integrity, and availability. Patch availability is expected through Ubiquiti's standard security update channels.

Affected products

  • Ubiquiti UniFi Protect

Timeline

  • 2026-08-26: disclosed

References

Related threats