CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-50746

CVSS 10.0v3.1pub. 2026-07-02upd. 2026-07-29

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.

🤖 AI Analysis
How it works

An attacker with access to the network where UniFi Connect Application operates can exploit improper access control (CWE-284) to send a malicious request. The lack of appropriate authorization mechanisms allows for command injection of system commands, which are subsequently executed by the host device with elevated privileges. The attack does not require authentication or user interaction, and its scope extends beyond the application (Scope: Changed).

Impact

An attacker can gain full control over the host device, including reading confidential data, modifying system configuration, or causing system unavailability. It is also possible to use the compromised device for further lateral movement within the network.

Mitigation & patch

Apply patches available from the manufacturer according to the references: https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc. It is also recommended to restrict network access to the UniFi Connect Application interface exclusively to trusted hosts using firewall or network segmentation until updates are deployed.

Who is affected

UniFi Connect Application — versions indicated in the manufacturer's references (Ubiquiti)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Ui Unifi Connect Application

    APP
    Ui
    < 3.24.20
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-34908CRITICAL10.0⚠ KEVPL ✓same vendor

Nieprawidłowa kontrola dostępu w UniFi OS — nieautoryzowane zmiany systemowe

CVE-2026-34909CRITICAL10.0⚠ KEVPL ✓same vendor

Path Traversal w UniFi OS — dostęp do plików systemowych i przejęcie konta

CVE-2026-34910CRITICAL10.0⚠ KEVPL ✓same vendor

Command Injection w UniFi OS via nieprawidłowa walidacja wejścia

CVE-2010-5330CRITICAL9.8⚠ KEVPL ✓same vendor

Command injection w Ubiquiti AirOS via stainfo.cgi (ifname)

CVE-2026-50747CRITICAL9.9PL ✓same vendor

SQL Injection w UniFi Talk Application umożliwia eskalację uprawnień