CVE 9.9 CRITICAL

CVE-2026-47370_CVE-2026-47370

9.9 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Command Injection within such UniFi OS devices or instances.

AI Analysis

Improper Input Validation vulnerability in UniFi OS devices, allowing Command Injection with low privileges.

Basic Information

ID CVE-2026-47370
Source hackerone
Published Jun 12, 2026 at 02:27

Affected Product

Vendor Ubiquiti Inc
Product UniFi OS Server
Affected Versions Ubiquiti Inc UniFi OS Server 0
Ubiquiti Inc Express 0
Ubiquiti Inc UDM 0
Ubiquiti Inc UDM-Pro 0
Ubiquiti Inc UDM-SE 0
Ubiquiti Inc UDM-Pro-Max 0
Ubiquiti Inc UDM-Beast 0
Ubiquiti Inc EFG 0
Ubiquiti Inc UDW 0
Ubiquiti Inc UDR 0
Ubiquiti Inc UDR7 0
Ubiquiti Inc UDR-5G 0
Ubiquiti Inc Express 7 0
Ubiquiti Inc UNVR 0
Ubiquiti Inc UNVR-Pro 0
Ubiquiti Inc UNVR-Instant 0
Ubiquiti Inc UNVR-G2 0
Ubiquiti Inc UNVR-G2-Pro 0
Ubiquiti Inc ENVR 0
Ubiquiti Inc ENVR-Core 0
Ubiquiti Inc UNAS-2 0
Ubiquiti Inc UNAS-4 0
Ubiquiti Inc UNAS-Pro 0
Ubiquiti Inc UNAS-Pro-4 0
Ubiquiti Inc UNAS-Pro-8 0
Ubiquiti Inc UCKP 0
Ubiquiti Inc UCK 0
Ubiquiti Inc UCK-Enterprise 0
Ubiquiti Inc UCG-Ultra 0
Ubiquiti Inc UCG-Max 0
Ubiquiti Inc UCG-Fiber 0
Ubiquiti Inc UCG-Industrial 0

CWE Classification

AI Assessment

AI Score 9.9 / 10
AI Severity Critical
Vendor Ubiquiti Inc
Product UniFi OS

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.