Junglewise Threat Intelligence

CVE-2026-77542: Ubiquiti UID Enterprise Agent command injection in input validation

CVE-2026-77542 · Severity: critical · CVSS 9.1 · Published 2026-08-26

Vendors: Ubiquiti.

Executive brief

Ubiquiti's UID Enterprise Agent is a network management tool used to monitor and control enterprise infrastructure. An attacker with network access and high privileges could inject malicious commands through improper input validation, potentially taking full control of monitored devices and disrupting network operations.

Technical details

This vulnerability is a command injection flaw resulting from improper input validation in Ubiquiti UID Enterprise Agent. The vulnerability requires the attacker to have network access and elevated privileges on the system. By crafting malicious input, an attacker can execute arbitrary system commands on the host device where the agent is running, leading to complete system compromise. The vulnerability was reported with a CVSS score of 9.1 (critical severity) and has not been observed exploited in the wild.

Affected products

  • Ubiquiti UID Enterprise Agent

Timeline

  • 2026-08-26: disclosed

References

Related threats