CVE-2026-77533

9.9

Ubiquiti · UniFi Protect Application

An improper input validation flaw in the UniFi Protect Application allows low-privileged network users to achieve command injection on the host device.

Executive summary

A critical command injection vulnerability in Ubiquiti UniFi Protect Application allows authenticated attackers with low privileges to execute arbitrary commands on the underlying host.

Vulnerability

This vulnerability stems from improper input validation (CWE-20) within the application, which facilitates command injection. An attacker with low-level network access can leverage this flaw to execute arbitrary system commands on the host device without user interaction.

Business impact

The potential for command injection on a network-attached security application presents a severe risk to organizational infrastructure. A successful exploit grants the attacker total control over the host device, which may lead to lateral movement within the network, surveillance data compromise, or complete system takeover. With a CVSS score of 9.9, this vulnerability is classified as critical, necessitating immediate attention to prevent unauthorized access and potential data exfiltration.

Remediation

Immediate Action: Update the Ubiquiti UniFi Protect Application to version 7.2.105 or higher immediately.

Proactive Monitoring: Monitor network traffic and system access logs for anomalous execution patterns or unauthorized attempts to reach the Protect application interface.

Compensating Controls: Restrict network access to the UniFi Protect interface to authorized management subnets only, and employ a Web Application Firewall (WAF) to filter malicious input strings if an immediate patch cannot be deployed.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical severity rating and the potential for full system compromise, organizations should prioritize patching this vulnerability across all affected deployments. Administrators must verify that the update to version 7.2.105 is successfully applied and confirm that no unauthorized changes were made to the system prior to the update. Do not delay these updates, as command injection flaws are frequently targeted by threat actors to establish persistent access.

More Ubiquiti CVEs

Sources