critical

Command Injection in UID Enterprise Agent (CVE-2026-47367)

critical-cve-against-infra · active

A critical Improper Input Validation flaw in the UID Enterprise Agent allows a low-privileged attacker with network access to execute command injection on the host device. Apply the vendor's fixed release as described in Ubiquiti's security bulletin.

Affected packages

Sources