VDB

GCVE-110-NCSC-2026-330

GCVE-110-NCSC-2026-330
Advisory PublishedCVSS 9.8/10
Vulnetix · Advisory published August 27, 2026
A low-privilege network attacker can exploit an Improper Input Validation vulnerability in the UniFi Protect Application to perform command injection on the host device.

Weaknesses (CWE)

CWE-489Active Debug CodeCWE-93Improper Neutralization of CRLF Sequences ('CRLF Injection')

Risk Scores

CVSS 3.1
9.8/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
Ubiquiti Incvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

867 records in the GCVE database · Updated September 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›