Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-77533: UniFi Protect lets low‑privilege network user run commands

CVE-2026-77533 · published 8 days ago
Summary

Someone with only basic network access can trick the UniFi Protect software into running commands on the server it runs on. This could let an attacker take control of the device or disrupt its operation. Apply the latest software update or patch from the vendor as soon as possible to fix the issue.

What to do
  • Update ubiquiti inc unifi protect application to version 7.2.105 or later.
Affected software
VendorProductAffected versions
ubiquiti inc unifi protect application < 7.2.105
Original advisory text
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the hos...
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.
Severity
9.9 Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS 1%
Type
CWE-20Improper Input Validation
Timeline
Published26 Aug 2026
Updated2 Sep 2026
First seen26 Aug 2026
Sources
CVE-2026-77533 · MITRE
Monitor software like this
Free during beta