CVE-2026-77537
10.0Ubiquiti · UniFi Protect Application
An improper input validation vulnerability in the Ubiquiti UniFi Protect Application allows unauthenticated network actors to execute arbitrary commands on the host device via command injection.
Executive summary
This critical command injection vulnerability in the Ubiquiti UniFi Protect Application allows unauthenticated remote attackers to achieve full system compromise.
Vulnerability
The application fails to properly validate user-supplied input, which permits an unauthenticated attacker on the network to inject and execute arbitrary system commands on the underlying host device.
Business impact
The ability for an unauthenticated attacker to execute arbitrary commands on a host device constitutes a total compromise of the affected system. Given the CVSS score of 10.0, this vulnerability poses an extreme risk to confidentiality, integrity, and availability, potentially allowing attackers to pivot into internal networks or exfiltrate sensitive video surveillance data.
Remediation
Immediate Action: Update the Ubiquiti UniFi Protect Application to version 7.2.105 or higher immediately.
Proactive Monitoring: Review system and application access logs for unusual network traffic or unexpected command execution patterns originating from unauthorized IP addresses.
Compensating Controls: Implement strict network segmentation to ensure the management interface of the UniFi Protect Application is not accessible to untrusted network segments.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Due to the critical nature of this vulnerability and the potential for complete host takeover, organizations must prioritize patching the UniFi Protect Application across all managed instances. Given that the flaw is easily exploitable by any actor with network access, failure to apply the update leaves the infrastructure exposed to high-impact remote code execution attacks.