Skip to main content
Mallory
Critical

Command Injection in UID Enterprise Agent

IdentifiersCVE-2026-47367CWE-20· Improper Input Validation

CVE-2026-47367 is an improper input validation vulnerability in UID Enterprise Agent. According to the provided content, a malicious actor with network access and low privileges can exploit insufficient validation of input handled by the agent to achieve command injection on the host device. The available material does not identify the specific vulnerable function or parameter, but it explicitly characterizes the issue as Improper Input Validation leading to command injection. The associated CVSS v3.1 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, indicating network-reachable exploitation, low attack complexity, no user interaction, and high impact across confidentiality, integrity, and availability.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows command injection on the host device running UID Enterprise Agent. Based on the provided CVSS vector and descriptions, this can result in high-impact compromise of the affected system, including unauthorized command execution with consequential loss of confidentiality, integrity, and availability. Because the scope is changed (S:C), exploitation may also affect resources beyond the vulnerable component’s original security boundary.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce exposure by restricting network access to UID Enterprise Agent to only trusted management sources, minimizing the number of low-privileged accounts that can reach or interact with the service, and monitoring for anomalous command execution or abuse of agent-related interfaces. Apply the vendor update as soon as operationally feasible, as no content-provided workaround fully addresses the underlying improper input validation flaw.

Remediation

Patch, then assume compromise.

Update UID Enterprise Agent to version 1.61.4, which is the version identified in the provided content as the recommended fix. Administrators should also consult Ubiquiti's official security advisory bulletin for product-specific update guidance and any additional affected-version details.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity5

Community discussion across Reddit, Mastodon, and other social sources.