Executive brief
UniFi Protect is a surveillance and video management system deployed by enterprises to monitor and secure physical locations. A network-accessible command injection vulnerability allows an attacker with network access to execute arbitrary commands on the host device, potentially leading to complete system compromise, data theft from surveillance footage, or operational disruption.
Technical details
This vulnerability is a command injection flaw arising from improper input validation in the UniFi Protect application. The vulnerability can be exploited by a network-adjacent attacker without authentication to inject and execute arbitrary operating system commands on the host device. The attack requires no user interaction and succeeds because user-supplied input is not properly sanitized before being passed to shell execution functions. Successful exploitation grants the attacker complete control over the host device, including read/write access to surveillance data, system configuration, and potential lateral movement within the network.
Affected products
- Ubiquiti UniFi Protect
Timeline
- 2026-08-26: disclosed