CVE-2026-47370: UniFi OS Command Injection via Improper Input Validation
ID: eb2034f5-acc8-519c-baf0-7c71597e63c5
STIX ID: report--eb2034f5-acc8-519c-baf0-7c71597e63c5
Feed Name: CosmicBytez Labs
A critical command-injection vulnerability (CVE-2026-47370, CVSS 9.9) in Ubiquiti UniFi OS allows low-privileged network attackers to inject shell metacharacters and execute arbitrary OS commands on UniFi devices (including UniFi Dream Machine, Dream Router, Cloud Gateway, and self-hosted UniFi OS instances). The advisory details technical mechanics, impact (arbitrary command execution, traffic interception, persistence, lateral movement), detection indicators, mitigation steps, and warns that chaining with CVE-2026-47369 enables full OS-level takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
