CVE-2026-33000

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ui:unifi_os_server:*:*:*:*:*:*:*:*

History

23 Jul 2026, 16:10

Type Values Removed Values Added
Summary
  • (es) Un actor malicioso con acceso a la red y privilegios elevados podría explotar una vulnerabilidad de validación de entrada incorrecta encontrada en dispositivos UniFi OS para ejecutar una inyección de comandos.

24 Jun 2026, 15:10

Type Values Removed Values Added
CPE cpe:2.3:a:ui:unifi_os_server:*:*:*:*:*:*:*:*
First Time Ui
Ui unifi Os Server
References () https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b - () https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b - Patch, Vendor Advisory

22 May 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-22 02:16

Updated : 2026-07-23 16:10


NVD link : CVE-2026-33000

Mitre link : CVE-2026-33000

CVE.ORG link : CVE-2026-33000


JSON object : View

Products Affected

ui

  • unifi_os_server
CWE
CWE-20

Improper Input Validation