CVE-2026-77540: Input Validation
Published Aug 26, 2026
·Updated
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device.
Affected Software
1 affected component
UniFi OS Server
Event History
Aug 26, 2026
CVE Published
via MITRE·09:53 AM
Data Sourced
via MITRE·09:53 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs network access to the UniFi OS Server and high privileges. No user interaction is required.
2
What could successful exploitation allow?
Successful exploitation could allow command injection on the host device, with high impact to confidentiality, integrity, and availability.