Executive brief
Ubiquiti's UID Enterprise Agent is a network management tool used to monitor and control enterprise infrastructure. An attacker with network access and high privileges could inject malicious commands through improper input validation, potentially taking full control of monitored devices and disrupting network operations.
Technical details
This vulnerability is a command injection flaw resulting from improper input validation in Ubiquiti UID Enterprise Agent. The vulnerability requires the attacker to have network access and elevated privileges on the system. By crafting malicious input, an attacker can execute arbitrary system commands on the host device where the agent is running, leading to complete system compromise. The vulnerability was reported with a CVSS score of 9.1 (critical severity) and has not been observed exploited in the wild.
Affected products
- Ubiquiti UID Enterprise Agent
Timeline
- 2026-08-26: disclosed