CVE-2026-77537
UniFi: Improper Input Validation (CVE-2026-77537)
Affected
- Ubiquiti/UniFi
= OS..OS
Description
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.
Source: BSI
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
OSMetrics
Show all metrics
Weakness classes (CWE)
CWE-20Class
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
cwe.mitre.org →
References & sources
Linked CVEs
- CVE-2026-77557
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to esca…
criticalCVSSv3 9.8 - CVE-2026-77554
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to…
criticalCVSSv3 10.0 - CVE-2026-77553
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Acc…
criticalCVSSv3 9.9 - CVE-2026-77552
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Enterprise Audio/Vid…
criticalCVSSv3 9.8 - CVE-2026-77551
A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulnerability found in…
criticalCVSSv3 9.0 - CVE-2026-77550
A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain de…
criticalCVSSv3 10.0 - CVE-2026-77549
A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vuln…
criticalCVSSv3 9.0 - CVE-2026-77548
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi P…
criticalCVSSv3 9.9 - CVE-2026-77547
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi A…
criticalCVSSv3 9.9 - CVE-2026-77546
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi A…
criticalCVSSv3 9.9 - CVE-2026-77545
A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerabilit…
criticalCVSSv3 9.0 - CVE-2026-77543
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi A…
criticalCVSSv3 9.9 - CVE-2026-77542
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UID En…
criticalCVSSv3 9.1 - CVE-2026-77541
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Ne…
criticalCVSSv3 9.1 - CVE-2026-77540
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi…
criticalCVSSv3 9.1 - CVE-2026-77539
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi…
criticalCVSSv3 9.1 - CVE-2026-77538
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to…
highCVSSv3 8.2 - CVE-2026-77537
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application…
criticalCVSSv3 10.0 - CVE-2026-77536
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain d…
criticalCVSSv3 9.9 - CVE-2026-77535
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi…
criticalCVSSv3 9.1 - CVE-2026-77534
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain d…
criticalCVSSv3 9.9 - CVE-2026-77533
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi P…
criticalCVSSv3 9.9