Critical severity9.8NVD Advisory· Published Apr 4, 2024· Updated Apr 15, 2026
CVE-2024-27981
CVE-2024-27981
Description
A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.0.28 and earlier) allows a malicious actor with UniFi Network Application Administrator credentials to escalate privileges to root on the host device.
Affected Products: UniFi Network Application (Version 8.0.28 and earlier) .
Mitigation: Update UniFi Network Application to Version 8.1.113 or later.
Affected products
1- Range: <=8.0.28
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.