Improper Input Validation in UniFi Access Application by Ubiquiti
CVE-2026-77546

9.9CRITICAL

Key Information:

Vendor
CVE Published:
26 August 2026

What is CVE-2026-77546?

The UniFi Access Application developed by Ubiquiti contains a vulnerability related to improper input validation. This weakness allows a malicious actor with low privileges who has access to the network to exploit the application and perform command injection on the host device. By manipulating input data, the attacker can execute unauthorized commands, potentially compromising the integrity and security of the affected systems. Users and administrators should ensure that they are running the latest patched versions to mitigate this risk.

Affected Version(s)

UniFi Access Application 0 < 4.3.5

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.