A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
References
| Link | Resource |
|---|---|
| https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b | Patch Vendor Advisory |
Configurations
History
23 Jul 2026, 16:10
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
24 Jun 2026, 15:10
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:ui:unifi_os_server:*:*:*:*:*:*:*:* | |
| First Time |
Ui
Ui unifi Os Server |
|
| References | () https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b - Patch, Vendor Advisory |
22 May 2026, 02:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-22 02:16
Updated : 2026-07-23 16:10
NVD link : CVE-2026-33000
Mitre link : CVE-2026-33000
CVE.ORG link : CVE-2026-33000
JSON object : View
Products Affected
ui
- unifi_os_server
CWE
CWE-20
Improper Input Validation
