CVE-2026-77547
9.9Ubiquiti · UniFi Access Application
An improper input validation vulnerability in the UniFi Access Application allows authenticated low-privileged network users to achieve remote command injection on the host device.
Executive summary
A critical command injection vulnerability in Ubiquiti UniFi Access Application allows authenticated attackers with low privileges to execute arbitrary commands on the host device.
Vulnerability
This vulnerability is a result of improper input validation (CWE-20) that permits command injection. It requires the attacker to have network access and low-level user privileges to trigger the flaw.
Business impact
The ability for an authenticated user to perform command injection poses a severe risk of total system compromise. Successful exploitation results in full control over the host device, potentially leading to unauthorized data access, lateral movement within the network, and significant operational disruption. With a CVSS score of 9.9, this vulnerability is classified as critical, necessitating immediate remediation to prevent unauthorized administrative control.
Remediation
Immediate Action: Update the Ubiquiti UniFi Access Application to version 4.3.5 or later to resolve the underlying input validation flaw.
Proactive Monitoring: Monitor network access logs for suspicious command execution patterns or unauthorized attempts to access management interfaces from low-privileged accounts.
Compensating Controls: Restrict network access to the UniFi Access Application management interface to authorized personnel only, utilizing network segmentation or internal firewalls to minimize the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the critical nature of this command injection vulnerability and its potential for full system compromise, organizations should prioritize patching as an urgent task. Ensure that all instances of the UniFi Access Application are updated to version 4.3.5 immediately. Failure to address this vulnerability could allow malicious actors with valid but low-privileged credentials to gain total control over critical infrastructure components.