Junglewise Threat Intelligence

CVE-2026-77540: Ubiquiti UniFi OS command injection vulnerability

CVE-2026-77540 · Severity: critical · CVSS 9.1 · Published 2026-08-26

Technologies: Ubiquiti UniFi OS. Vendors: Ubiquiti.

Executive brief

UniFi OS is network management software used by organizations to configure and monitor network infrastructure devices. A vulnerability in the OS allows a privileged network-connected attacker to inject and execute arbitrary commands on the host device, potentially gaining full control of the system and the ability to modify network configurations or access sensitive data.

Technical details

An improper input validation vulnerability in UniFi OS Server allows command injection on the host device. The vulnerability requires the attacker to have network access and high privileges to exploit it. By sending crafted input that bypasses validation checks, an attacker can inject and execute arbitrary system commands with the privileges of the UniFi OS process. This could lead to complete system compromise, unauthorized access to network credentials, or lateral movement within the network infrastructure.

Affected products

  • Ubiquiti UniFi OS

Timeline

  • 2026-08-26: disclosed

References

Related threats