Junglewise Threat Intelligence

CVE-2026-77547: Ubiquiti UniFi Access command injection in input validation

CVE-2026-77547 · Severity: critical · CVSS 9.9 · Published 2026-08-26

Technologies: Ubiquiti UniFi Access. Vendors: Ubiquiti.

Executive brief

UniFi Access is a network access control system used to manage authentication and authorization for enterprise networks. An attacker with network access and low privileges can inject malicious commands through improperly validated input, gaining the ability to execute arbitrary code on the access control device and potentially compromise network security.

Technical details

The vulnerability is a command injection flaw resulting from improper input validation in the UniFi Access application. An attacker with network access and low privileges can craft malicious input that bypasses validation checks, allowing arbitrary command execution on the host device. The attack requires network access but not prior authentication at an elevated privilege level. Successful exploitation allows the attacker to execute system commands with the privileges of the vulnerable application, potentially leading to full device compromise.

Affected products

  • Ubiquiti UniFi Access <UNKNOWN>

Timeline

  • 2026-08-26: disclosed
  • 2026-08-26: advisory: Security Advisory Bulletin 067 published

References

Related threats