Cyber Security News

Ubiquiti Fixes 22 UniFi Flaws Enabling Command Injection, Authentication Bypass and Privilege Escalation

Ubiquiti has released security updates to address 22 vulnerabilities across its UniFi ecosystem. These updates include multiple critical flaws that could allow unauthenticated command injection, authentication bypass, and privilege escalation on exposed devices.

Documented in Security Advisory Bulletin 067 and published on August 26, 2026, these vulnerabilities affect several components, including UniFi OS, UniFi Protect, UniFi Network, UniFi Access, UniFi Talk, UniFi Connect, UID Enterprise Agent, and various hardware appliances. Most vulnerabilities carry critical CVSS scores, with several rated at 10.0.

Ubiquiti Fixes 22 UniFi Flaws

The most severe issues include CVE-2026-77537, CVE-2026-77550, and CVE-2026-77554, each with a CVSS score of 10.0 and exploitable remotely without authentication or user interaction.

CVE-2026-77537 affects UniFi Protect Application versions 7.1.87 and earlier, allowing command injection on the host device due to improper input validation. Ubiquiti has resolved this flaw in version 7.2.105.

CVE-2026-77550 is an authentication-bypass vulnerability in UniFi OS, resulting from improper handling of CRLF sequences. A remote attacker could exploit this issue to bypass authentication on affected UniFi OS devices or instances.

The affected devices include UniFi OS Server, Cloud Keys, Network Video Recorders, Dream Machines, Cloud Gateways, Dream Routers, Dream Wall, Enterprise Firewall Core, and other appliances.

The bulletin also highlights multiple command-injection flaws in UniFi Protect, UniFi Network, UniFi Access, UniFi Talk, UID Enterprise Agent, UniFi OS Server, and the UniFi Enterprise Audio/Video Bridge.

Successful exploitation could allow an attacker to execute arbitrary commands either on the host system or an adopted device, depending on the specific product affected.

Several vulnerabilities require low-privileged access, making them particularly significant in environments where attackers may already have access to a restricted UniFi account.

For instance, CVE-2026-77533, CVE-2026-77543, CVE-2026-77546, CVE-2026-77547, and CVE-2026-77548 allow low-privileged users to exploit command-injection pathways affecting Protect or Access deployments.

Ubiquiti has also patched privilege escalation flaws in UniFi OS, UniFi Network, UniFi Connect, UniFi Access, UniFi Connect Display Cast Pro, and UniFi Protect AI Key.

Notably, CVE-2026-77538, which affects the UniFi Connect Application, can reportedly be chained with dependency vulnerabilities to escalate privileges on the host device.

CVE Details

CVEVulnerabilityAffected product and versionCVSSFixed version
CVE-2026-77533Command injectionUniFi Protect ≤7.1.879.97.2.105
CVE-2026-77534Privilege escalationUniFi OS Server ≤5.1.21; devices ≤5.1.269.9Server 5.1.37; devices 5.1.31/5.1.32
CVE-2026-77535Command injectionUniFi Network ≤10.4.579.110.5.67
CVE-2026-77536Privilege escalationUniFi OS Server ≤5.1.21; devices ≤5.1.269.9Server 5.1.37; devices 5.1.31/5.1.32
CVE-2026-77537Unauthenticated command injectionUniFi Protect ≤7.1.8710.07.2.105
CVE-2026-77538Privilege escalationUniFi Connect ≤3.24.208.23.24.22
CVE-2026-77539Command injectionUniFi OS Server ≤5.1.219.15.1.37
CVE-2026-77540Command injectionUniFi OS Server ≤5.1.219.15.1.37
CVE-2026-77541Privilege escalationUniFi Network ≤10.4.579.110.5.67
CVE-2026-77542Command injectionUID Enterprise Agent ≤1.61.89.11.62.1
CVE-2026-77543Command injectionUniFi Access ≤4.3.39.94.3.5
CVE-2026-77545Privilege escalation via active debug codeUniFi OS Server/devices9.0Server 5.1.37; devices 5.1.31/5.1.32
CVE-2026-77546Command injectionUniFi Access ≤4.3.39.94.3.5
CVE-2026-77547Command injectionUniFi Access ≤4.3.39.94.3.5
CVE-2026-77548Command injectionUniFi Protect ≤7.1.879.97.2.105
CVE-2026-77549Authentication bypass via CRLF injectionUniFi OS Server/devices; Express ≤4.0.169.0Server 5.1.37; devices 5.1.31/5.1.32; Express 4.0.17
CVE-2026-77550Unauthenticated authentication bypass via CRLF injectionUniFi OS Server/devices; Express ≤4.0.1610.0Server 5.1.37; devices 5.1.31/5.1.32; Express 4.0.17
CVE-2026-77551Privilege escalationUniFi Connect Display Cast Pro ≤1.0.1089.01.0.111
CVE-2026-77552Unauthenticated command injectionEnterprise Audio/Video Bridge ≤1.0.109.81.0.11
CVE-2026-77553Privilege escalationUniFi Access ≤4.3.39.94.3.5
CVE-2026-77554Unauthenticated command injectionUniFi Talk ≤5.2.710.05.3.2
CVE-2026-77557Privilege escalationUniFi Protect AI Key ≤2.1.39.82.2.6

Organizations should prioritize updates for internet-accessible UniFi management systems, video surveillance deployments, access control infrastructure, and gateway appliances.

Administrators should also restrict management interfaces to trusted networks, review privileged UniFi accounts, and monitor logs for any anomalous administrative activity, unexpected command execution, or suspicious authentication events.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

CISA Warns of Actively Exploited Citrix NetScaler ADC and Gateway Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-8452, a vulnerability affecting Citrix…

7 minutes ago

Hackers Are Targeting AI Servers to Steal API Keys and Hijack Computing Power

AI infrastructure is rapidly becoming a high-value enterprise attack surface. Attackers targeting LiteLLM AI gateways,…

10 minutes ago

TP-Link Kasa Smart Home Flaw Lets Attackers Forge Control Messages and Take Control of Devices

TP-Link has revealed a critical vulnerability in Kasa smart home devices that could allow an…

21 minutes ago

Ransomware Hacker Uses AI to Plan Attacks and Compromises More Than 20 Organizations

A Russian-speaking affiliate of the Aurora ransomware operation compromised more than 20 organizations across nine…

1 hour ago

CISA Warns of Actively Exploited Microsoft SQL Server RCE Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2019-1068, a remote code execution…

1 hour ago

FBI Seizes China State-Sponsored Hacker Platforms Used to Target U.S. Critical Infrastructure

The U.S. Justice Department and the FBI have seized domains associated with two hacking platforms…

2 hours ago