CVE-2026-77539: Input Validation
Published Aug 26, 2026
·Updated
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device.
Affected Software
1 affected component
Ubiquiti UniFi OS Server
Event History
Aug 26, 2026
CVE Published
via MITRE·09:50 AM
Data Sourced
via MITRE·09:50 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must have network access and high privileges. The provided information does not indicate that unauthenticated or low-privileged users can exploit it.
2
What is the potential impact if exploitation succeeds?
Successful exploitation allows command injection on the host device. The CVSS vector indicates high impact to confidentiality, integrity, and availability, with impact extending beyond the vulnerable security authority.