CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-54402

Critical · CVSS 9.9

UniFi OS — Improper Input Validation Command Injection

CVSS
9.9
nvd
EPSS
KEV
No
Class
kernel local
CWE-20, CWE-77

Description

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.

Search profile — drives PoC discovery

Symbols UniFi OScommand injectioninput validationkernel_localCWE-20CWE-77network low privilege
Keywords CVE-2026-54402UniFi OS command injectionUniFi OS RCEUniFi OS exploitUniFi OS PoCUbiquiti UniFi command injectionUniFi OS improper input validationSecurity Advisory Bulletin 066
Versions: <UNKNOWN>

References

Status: enriched · ingested 2026-07-10T06:00:46.000Z · profiled 2026-07-10T06:30:26.000Z