Home

Description

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

PUBLISHED Reserved 2026-03-17 | Published 2026-05-22 | Updated 2026-05-23 | Assigner hackerone




CRITICAL: 9.1CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Problem types

CWE-20 Improper Input Validation

Product status

Default status
unaffected

Any version before 5.0.8
affected

References

community.ui.com/...064/84811c09-4cf4-42ab-bd61-cc994445963b

cve.org (CVE-2026-33000)

nvd.nist.gov (CVE-2026-33000)

Download JSON