Junglewise Threat Intelligence

CVE-2026-77535: Ubiquiti UniFi Network Application command injection via improper input validation

CVE-2026-77535 · Severity: critical · CVSS 9.1 · Published 2026-08-26

Technologies: Ubiquiti UniFi Network Application. Vendors: Ubiquiti.

Executive brief

UniFi Network Application is a centralized management platform for Ubiquiti network devices. A privileged network-based attacker can exploit improper input validation to inject and execute arbitrary commands on adopted network devices, potentially compromising network infrastructure, intercepting traffic, or disrupting service availability.

Technical details

The vulnerability is an Improper Input Validation flaw in the UniFi Network Application that permits Command Injection attacks. An attacker with network access and high privileges can supply malicious input that is not properly sanitized before being executed on an adopted device managed by the application. This allows remote code execution on network devices under UniFi management. The attack requires both network reachability to the application and elevated privileges. No information on available patches was provided in the advisory excerpt.

Affected products

  • Ubiquiti UniFi Network Application <UNKNOWN>

Timeline

  • 2026-08-26: disclosed

References

Related threats