Command Injection Vulnerability in UniFi Network Application
CVE-2024-27981
9.8CRITICAL
What is CVE-2024-27981?
A command injection vulnerability exists in the self-hosted UniFi Network Servers running the UniFi Network Application version 8.0.28 and earlier. This flaw allows a malicious actor, who possesses valid UniFi Network Application Administrator credentials, to escalate privileges to root on the host device, thereby compromising system integrity. It is crucial for administrators to upgrade to UniFi Network Application version 8.1.113 or later to remediate this security risk.
Affected Version(s)
UniFi Network Application 8.1.113
News Articles

CVE-2024-27981 Archives
VulnerabilityMarch 26, 2024CVE-2024-27981: Critical Vulnerability Patched in Ubiquiti UniFi Network ApplicationUbiquiti Networks has released an urgent security update for its popular UniFi Network...