CVE-2026-77548: Input Validation
Published Aug 26, 2026
·Updated
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.
Affected Software
1 affected component
UniFi Protect Application
Event History
Aug 26, 2026
CVE Published
via MITRE·10:23 AM
Data Sourced
via MITRE·10:23 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Is user interaction required for exploitation?
No. The CVSS vector indicates that no user interaction is required.
2
What impact could successful exploitation have?
The CVSS vector rates confidentiality, integrity, and availability impact as high. It also indicates a changed scope.
3
Is the attack considered complex to carry out once the attacker has the required access?
No. The CVSS vector rates attack complexity as low.