CVE-2026-77548

9.9

Ubiquiti · UniFi Protect Application

An improper input validation vulnerability in the Ubiquiti UniFi Protect Application allows authenticated attackers with low privileges to execute arbitrary commands on the underlying host device.

Executive summary

A critical command injection vulnerability in Ubiquiti UniFi Protect Application allows low-privileged network users to achieve full system compromise.

Vulnerability

This flaw is caused by improper input validation, which enables a command injection attack. An attacker with low-level network access and authentication can interact with the application to execute arbitrary system commands on the host device.

Business impact

The ability to execute arbitrary commands on a host device presents a severe risk to organizational infrastructure. Successful exploitation grants the attacker full control over the affected system, potentially leading to unauthorized data exfiltration, lateral movement within the network, and total system disruption. Given the CVSS score of 9.9, this vulnerability is categorized as critical and requires immediate attention to prevent catastrophic security failures.

Remediation

Immediate Action: Update the Ubiquiti UniFi Protect Application to version 7.2.105 or later immediately.

Proactive Monitoring: Review system and application access logs for suspicious command execution patterns or unauthorized attempts to access network administration functions.

Compensating Controls: Implement strict network segmentation to isolate the UniFi Protect Application from critical internal resources, and deploy WAF rules to inspect and filter potentially malicious input strings.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The vulnerability represents a critical risk to the security and integrity of the UniFi Protect deployment. Organizations should prioritize updating to version 7.2.105 as the primary method of remediation. Due to the high impact of command injection, ensure that access to the management interface is restricted to authorized personnel only while the update is being staged.

More Ubiquiti CVEs

Sources