VDB
GCVE-110-NCSC-2026-330
GCVE-110-NCSC-2026-330
Advisory PublishedCVSS 9.8/10
A low-privilege network attacker can exploit an Improper Input Validation vulnerability in the UniFi Protect Application to perform command injection on the host device.
Weaknesses (CWE)
CWE-489Active Debug CodeCWE-93Improper Neutralization of CRLF Sequences ('CRLF Injection')
Risk Scores
CVSS 3.1
9.8/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Ubiquiti Inc | vers:unknown/* | — | — |
Aliases
CVE-2026-77533CVE-2026-77534CVE-2026-77535CVE-2026-77536CVE-2026-77537CVE-2026-77538CVE-2026-77539CVE-2026-77540CVE-2026-77541CVE-2026-77542CVE-2026-77543CVE-2026-77545CVE-2026-77546CVE-2026-77547CVE-2026-77548CVE-2026-77549CVE-2026-77550CVE-2026-77551CVE-2026-77552CVE-2026-77553CVE-2026-77554CVE-2026-77557
Browse GCVE Records
867 records in the GCVE database · Updated September 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.