Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-77543: UniFi Access app could let attackers run commands
CVE-2026-77543 · published 8 days ago
Summary
The UniFi Access application does not properly check user input, so someone on the network with limited access can send specially crafted data that makes the system run arbitrary commands. This could allow an attacker to take control of the host or disrupt services. Install the latest update from the vendor or apply a fix that validates input promptly.
What to do
- Update ubiquiti inc unifi access application to version 4.3.5 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ubiquiti inc | unifi access application | < 4.3.5 |
Original advisory text
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host...
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.
Severity
9.9
Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-20Improper Input Validation
Timeline
Published26 Aug 2026
Updated2 Sep 2026
First seen26 Aug 2026
Monitor software like this
Free during beta