Executive brief
UniFi Network Application is a centralized management platform for Ubiquiti network devices. A privileged network-based attacker can exploit improper input validation to inject and execute arbitrary commands on adopted network devices, potentially compromising network infrastructure, intercepting traffic, or disrupting service availability.
Technical details
The vulnerability is an Improper Input Validation flaw in the UniFi Network Application that permits Command Injection attacks. An attacker with network access and high privileges can supply malicious input that is not properly sanitized before being executed on an adopted device managed by the application. This allows remote code execution on network devices under UniFi management. The attack requires both network reachability to the application and elevated privileges. No information on available patches was provided in the advisory excerpt.
Affected products
- Ubiquiti UniFi Network Application <UNKNOWN>
Timeline
- 2026-08-26: disclosed