Executive brief
UniFi OS is a management platform used to deploy and control network infrastructure across enterprise environments. A command injection vulnerability allows a privileged network attacker to execute arbitrary commands on the host device, potentially compromising network management, customer data access, and operational availability across all connected network devices.
Technical details
This is an Improper Input Validation vulnerability (CWE-20) in UniFi OS Server that allows command injection. An attacker with network access and high privileges can exploit inadequate input validation to inject and execute arbitrary commands on the host device. The vulnerability requires both network connectivity and elevated privileges as preconditions. Successful exploitation grants arbitrary code execution on the UniFi OS host with the privileges of the running service, allowing complete system compromise.
Affected products
- Ubiquiti UniFi OS
Timeline
- 2026-08-26: disclosed