Security Advisory

CVE-2024-27981

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-04-04 22:16:29
Last updated 2025-03-18 20:10:28
Assigner hackerone
State PUBLISHED

Description

A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.0.28 and earlier) allows a malicious actor with UniFi Network Application Administrator credentials to escalate privileges to root on the host device. Affected Products: UniFi Network Application (Version 8.0.28 and earlier) . Mitigation: Update UniFi Network Application to Version 8.1.113 or later.