CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-33000

CVSS 9.1v3.1pub. 2026-05-22upd. 2026-06-24

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

🤖 AI Analysis
How it works

An attacker with network access and high system privileges can deliver improperly validated input data to the vulnerable UniFi OS component. Lack of proper input validation (CWE-20) allows embedding malicious system commands in the input data, which are then executed by the device. Network attack vector (AV:N) and lack of user interaction requirement (UI:N) mean that the exploit can be performed remotely and fully automatically.

Impact

Successful exploitation of the vulnerability gives an attacker the ability to remotely execute arbitrary system commands on the device (RCE), which can lead to complete takeover of the device, breach of confidentiality and integrity of data, and denial of service (C:H/I:H/A:H). The scope of impact includes resources beyond the component itself (S:C), which increases the risk of lateral movement in the network.

Mitigation & patch

Apply patches available from the manufacturer according to the references — details regarding fixed versions of UniFi OS software are contained in the security bulletin available at: https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b

Who is affected

Devices running UniFi OS — specific versions indicated in the manufacturer's references (Ubiquiti Security Advisory Bulletin 064)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Ui Unifi Os Server

    APP
    Ui
    < 5.0.8
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-34909CRITICAL10.0⚠ KEVPL ✓same product

Path Traversal w UniFi OS — dostęp do plików systemowych i przejęcie konta

CVE-2026-34910CRITICAL10.0⚠ KEVPL ✓same product

Command Injection w UniFi OS via nieprawidłowa walidacja wejścia

CVE-2026-34908CRITICAL10.0⚠ KEVPL ✓same product

Nieprawidłowa kontrola dostępu w UniFi OS — nieautoryzowane zmiany systemowe

CVE-2026-54402CRITICAL9.9PL ✓same product

Command Injection w UniFi OS przez błąd walidacji wejścia

CVE-2026-55110HIGH7.5PL ✓same product

Błędna konfiguracja CORS w UniFi OS umożliwia przejęcie sesji użytkownika