Junglewise Threat Intelligence

CVE-2026-77537: Ubiquiti UniFi Protect command injection via improper input validation

CVE-2026-77537 · Severity: critical · CVSS 10 · Published 2026-08-26

Technologies: Ubiquiti UniFi Protect. Vendors: Ubiquiti.

Executive brief

UniFi Protect is a surveillance and video management system deployed by enterprises to monitor and secure physical locations. A network-accessible command injection vulnerability allows an attacker with network access to execute arbitrary commands on the host device, potentially leading to complete system compromise, data theft from surveillance footage, or operational disruption.

Technical details

This vulnerability is a command injection flaw arising from improper input validation in the UniFi Protect application. The vulnerability can be exploited by a network-adjacent attacker without authentication to inject and execute arbitrary operating system commands on the host device. The attack requires no user interaction and succeeds because user-supplied input is not properly sanitized before being passed to shell execution functions. Successful exploitation grants the attacker complete control over the host device, including read/write access to surveillance data, system configuration, and potential lateral movement within the network.

Affected products

  • Ubiquiti UniFi Protect

Timeline

  • 2026-08-26: disclosed

References

Related threats