logo

CVE-2026-47370: UniFi OS Command Injection via Improper Input Validation

ID: eb2034f5-acc8-519c-baf0-7c71597e63c5

STIX ID: report--eb2034f5-acc8-519c-baf0-7c71597e63c5

Feed Name: CosmicBytez Labs

Threat Score
92/100

Date Published: 2026-06-12

Date Updated: 2026-06-13

...
...

A critical command-injection vulnerability (CVE-2026-47370, CVSS 9.9) in Ubiquiti UniFi OS allows low-privileged network attackers to inject shell metacharacters and execute arbitrary OS commands on UniFi devices (including UniFi Dream Machine, Dream Router, Cloud Gateway, and self-hosted UniFi OS instances). The advisory details technical mechanics, impact (arbitrary command execution, traffic interception, persistence, lateral movement), detection indicators, mitigation steps, and warns that chaining with CVE-2026-47369 enables full OS-level takeover.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.