Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-77548: UniFi Protect lets low‑privilege network users run commands

CVE-2026-77548 · published 8 days ago
Summary

The UniFi Protect application does not properly check data it receives, allowing someone on the same network with limited rights to run unauthorized commands on the server. This could let an attacker take control of the device or disrupt its operation. Apply the vendor’s update or patch as soon as possible and restrict network access to trusted users.

What to do
  • Update ubiquiti inc unifi protect application to version 7.2.105 or later.
Affected software
VendorProductAffected versions
ubiquiti inc unifi protect application < 7.2.105
Original advisory text
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the hos...
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.
Severity
9.9 Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-20Improper Input Validation
Timeline
Published26 Aug 2026
Updated30 Aug 2026
First seen26 Aug 2026
Sources
CVE-2026-77548 · MITRE
Monitor software like this
Free during beta