CVE-2026-77552

UniFi: Improper Input Validation (CVE-2026-77552)

criticalEPSS 1.6%

Affected

  • Ubiquiti/UniFi = OS..OS

Description

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Enterprise Audio/Video Bridge to execute a Command Injection on the device.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

UbiquitiUniFi
OS

Metrics

9.8
Source: cna-v3
75.6 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
1.6 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-08-26 11:16 UTC
CWE-20

Weakness classes (CWE)

  • CWE-20Class

    Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

    cwe.mitre.org →

References & sources