CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-50747

CVSS 9.9v3.1pub. 2026-07-02upd. 2026-07-09

A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device.

🤖 AI Analysis
How it works

An attacker with network access and an account with low privileges can exploit a series of SQL Injection vulnerabilities present in the UniFi Talk application. Through crafted SQL queries injected into vulnerable application endpoints, it is possible to gain unauthorized access to data and escalate privileges at the host device level. The vulnerability requires only low-privilege authentication, which significantly lowers the threshold for its exploitation.

Impact

An attacker can perform privilege escalation on the host device, potentially gaining full control of the system, including access to sensitive data, ability to modify configuration, and compromise of service integrity and availability.

Mitigation & patch

Security patches from the manufacturer should be applied according to references — details in Security Advisory Bulletin 066 available at: https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc

Who is affected

UniFi Talk application — versions indicated in manufacturer references (Security Advisory Bulletin 066)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Ui Unifi Talk Application

    APP
    Ui
    < 5.2.2
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
SQLiLPE
CWE
References

Related vulnerabilities

CVE-2026-55113HIGH7.5PL ✓same product

SSRF w UniFi Talk Application — DoS i ominięcie uwierzytelnienia

CVE-2026-55119HIGH8.1PL ✓same product

Privilege Escalation w UniFi Talk Application (Improper Access Control)

CVE-2026-34909CRITICAL10.0⚠ KEVPL ✓same vendor

Path Traversal w UniFi OS — dostęp do plików systemowych i przejęcie konta

CVE-2026-34908CRITICAL10.0⚠ KEVPL ✓same vendor

Nieprawidłowa kontrola dostępu w UniFi OS — nieautoryzowane zmiany systemowe

CVE-2026-34910CRITICAL10.0⚠ KEVPL ✓same vendor

Command Injection w UniFi OS via nieprawidłowa walidacja wejścia