Junglewise Threat Intelligence

CVE-2026-77543: Ubiquiti UniFi Access command injection via improper input validation

CVE-2026-77543 · Severity: critical · CVSS 9.9 · Published 2026-08-26

Technologies: Ubiquiti UniFi Access. Vendors: Ubiquiti.

Executive brief

UniFi Access is a network access control system used to manage authentication and authorization to corporate networks. An attacker with network access and low privileges can inject arbitrary commands through the application, leading to complete compromise of the access control device and potentially lateral movement into the broader network.

Technical details

UniFi Access contains an Improper Input Validation vulnerability (CWE-20) that allows command injection attacks. An authenticated attacker with low privileges and network access to the device can craft malicious input that bypasses validation filters, leading to arbitrary command execution on the host system. This vulnerability requires network access and some level of authentication or low-privilege account access. Successful exploitation grants an attacker the ability to execute arbitrary commands with the privileges of the UniFi Access application, potentially leading to full device compromise. Ubiquiti has published security advisory bulletin 067 addressing this vulnerability.

Affected products

  • Ubiquiti UniFi Access

Timeline

  • 2026-08-26: disclosed

References

Related threats