Executive brief
UniFi Protect is a video surveillance and access control platform used by organizations to monitor premises and secure entry points. An attacker with network access and low privileges could inject malicious commands through improper input validation, potentially gaining complete control of the host device and compromising all connected surveillance systems.
Technical details
This vulnerability stems from improper input validation in UniFi Protect Application, allowing an unauthenticated or low-privileged network-accessible attacker to perform command injection on the host device. The vulnerability requires network access but does not require high privileges or user interaction. A successful exploit enables arbitrary command execution with the privileges of the UniFi Protect process, potentially leading to full system compromise. Patches or mitigations should be available through Ubiquiti's security advisory bulletin.
Affected products
- Ubiquiti UniFi Protect
Timeline
- 2026-08-26: disclosed