Sceawere

Vulnerability Detail

CVE-2026-77537UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

UniFi Protect Command Injection Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
10
Creation Date
9h ago
Vendor
Ubiquiti Inc
Product
UniFi Protect Application
Attack Type
CWE-20 Improper input validation
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "10.0",
  "pubDate": "2026-08-26T10:16:41.540Z",
  "pubdate": "2026-08-26T10:16:41.540Z",
  "executiveSummary": "The UniFi Protect Application contains an Improper Input Validation vulnerability that facilitates remote command injection.\nThis vulnerability resides within the application's input processing logic, allowing a network-adjacent attacker to inject and execute arbitrary system-level commands on the underlying host device.\nThe primary impact of this flaw is full system compromise, as the injected commands are executed with the privileges of the UniFi Protect service, often leading to root-level access on the host operating system.\nThe vulnerability requires the attacker to have existing network access to the target infrastructure; however, it does not necessarily mandate prior authentication to the application, depending on the specific endpoint exposure.\nSuccessful exploitation allows for complete takeover of the affected device, potentially leading to unauthorized data access, persistence installation, and lateral movement within the network.\nOrganizations using UniFi Protect are at high risk if the application is exposed to untrusted networks without sufficient segmentation or external perimeter defenses.",
  "technicalDetails": "The vulnerability is rooted in a failure to perform adequate input validation and sanitization on user-supplied data processed by the UniFi Protect Application. When the application receives malicious input, it fails to properly escape or validate the payload before passing it to system-level calls or shell interpreters.\nThe attack flow begins when an attacker sends a specially crafted request containing shell metacharacters (e.g., ;, |, &, backticks) or command sequences to a vulnerable endpoint within the UniFi Protect service. The application, failing to enforce strict allow-listing or schema validation, inadvertently incorporates this malicious input into a backend system command execution chain.\nBecause the UniFi Protect service typically operates with elevated privileges to manage hardware and system resources, the injected command inherits the process's execution context. This allows an attacker to execute arbitrary binaries, modify system configuration files, install backdoors, or exfiltrate sensitive data from the host device.\nExploitation typically involves identifying an internal API endpoint or service component that acts as a bridge between network traffic and local system command execution. By manipulating parameters that are subsequently utilized in system-level operations (such as executing utility scripts or management tasks), the attacker triggers the command injection.\nThe post-exploitation impact is severe. Upon successful execution, the attacker gains the ability to manipulate the host environment beyond the scope of the application. They can establish persistence through cron jobs or systemd services, disable logging to hide tracks, and utilize the host as a pivot point to perform internal network reconnaissance or deliver further payloads. The lack of robust input validation means that even common shell-based attacks are highly effective, as the underlying system lacks secondary defenses that would otherwise catch or neutralize anomalous command execution attempts.\nThe vulnerability is exacerbated by the highly integrated nature of the UniFi Protect Application, where the software often manages critical system functions. Therefore, an attacker compromising the application effectively gains control over the host device's operations, making this a critical-severity security flaw."
}
CVE-2026-77537: UniFi Protect Command Injection Vulnerability (CRITICAL Severity, CVSS: 10.0) - Sceawere