Visualização de leitura

Ubiquiti Fixes Critical CVE-2026-50746 and Multiple UniFi OS Vulnerability Flaws

CVE-2026-50746

Ubiquiti has released security updates to address several critical security flaws, led by CVE-2026-50746, a maximum-severity UniFi OS vulnerability with a CVSS score of 10.0. Published in Security Advisory Bulletin 066 on July 2, 2026, the update resolves 25 vulnerabilities affecting UniFi OS and multiple applications, including UniFi Connect, Talk, Access, Protect, and Network. 

CVE-2026-50746 Tops List of Critical UniFi OS Vulnerability Patches 

The most severe issue, CVE-2026-50746, affects UniFi Connect Application versions 3.4.16 and earlier. The software is used to manage commercial building operations, including smart LED lighting systems and electric vehicle chargers, from a centralized interface.  According to Ubiquiti, "A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device."  The advisory recommends upgrading the UniFi Connect Application to version 3.4.20 or later. The flaw carries a CVSS v3.1 score of 10.0 with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H and was reported by Duc Anh Nguyen (@heckintosh_). 

Additional UniFi OS vulnerability fixes 

Alongside CVE-2026-50746, Ubiquiti patched six additional critical vulnerabilities on Thursday. These include CVE-2026-50747 and CVE-2026-50748, affecting UniFi Talk and UniFi Access, respectively, both carrying CVSS scores of 9.9. The company also fixed CVE-2026-54402, a command injection flaw in UniFi OS; CVE-2026-55115, an SSRF vulnerability in UniFi Protect; and CVE-2026-55116, an improper access control issue that allowed unauthorized changes to affected devices. Each requires software updates to the latest supported releases.  The advisory also addresses several high-severity vulnerabilities, including CVE-2026-54401 (SSRF), CVE-2026-54403 (path traversal), CVE-2026-54404 (SQL injection), and multiple authentication bypass, privilege escalation, denial-of-service, path traversal, SQL injection, CORS, and improper access control flaws affecting UniFi OS, UniFi Network, UniFi Protect, UniFi Talk, UniFi Access, and UniFi Protect Floodlight.  Notably, Ubiquiti warned that CVE-2026-54403 can be chained with other vulnerabilities to remove the requirement for low-privileged access, increasing its exploitation potential.  Affected products include UniFi OS Server, UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, Cloud Key devices, UNVR systems, ENVR platforms, UCG appliances, EF-Core, and multiple UNAS storage products running vulnerable software versions.  Ubiquiti advises customers to update UniFi OS devices to version 5.1.19 or later, where applicable, and to upgrade UniFi Talk to version 5.2.2, UniFi Access to version 4.2.29, UniFi Protect to version 7.1.83, and UniFi Network to version 10.4.57. Prompt installation of these updates is recommended to mitigate the risks associated with CVE-2026-50746 and the broader UniFi OS vulnerability disclosures. 

Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation

Ubiquiti patched seven UniFi OS flaws, including critical CVE-2026-50746, which allows command injection in UniFi Connect Application.

Ubiquiti released security updates for seven critical UniFi OS vulnerabilities, including a maximum-severity flaw, tracked as CVE-2026-50746 (CVSS score of 10.0), enabling command injection attacks.

The issue affects UniFi Connect Application versions 3.4.16 and earlier, a platform used to manage commercial building systems such as smart lighting and EV chargers. Organizations using affected versions should update promptly to reduce compromise risks.

“A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.” reads the advisory.

The vendor also addressed thcritical vulnerabilities:

  • CVE-2026-50747 (CVSS score of 9.9): The vulnerability affects UniFi Talk Application and consists of authenticated SQL injection flaws. A low-privileged attacker with network access can exploit the issue to escalate privileges and gain greater control over the host device.
  • CVE-2026-50748 (CVSS score of 9.9): The vulnerability affects UniFi Access Application and is caused by improper input validation. A low-privileged attacker with network access can exploit the flaw to execute commands on the host device.
  • CVE-2026-54400 (CVSS score of 9.1): The vulnerability affects UniFi Access Application and is caused by improper access control. A high-privileged attacker can exploit it to escalate privileges on the affected host device.
  • CVE-2026-54402 (CVSS score of 9.9): The vulnerability affects multiple UniFi OS devices and allows a low-privileged attacker with network access to exploit an SSRF vulnerability, potentially leading to privilege escalation within UniFi OS environments.
  • CVE-2026-55115 (CVSS score of 9.9): The vulnerability affects UniFi OS/UniFi Protect environments and is related to a CORS misconfiguration. An attacker can abuse a victim’s authenticated session to perform unauthorized actions.
  • CVE-2026-55116 (CVSS score of 9.0): The vulnerability affects certain UniFi OS devices and allows unauthorized changes through an improper access control issue under specific network conditions.

Ubiquiti recommends updating affected products to the fixed versions listed in Security Advisory Bulletin 066.

Ubiquiti has not confirmed whether any of the vulnerabilities were exploited in attacks in the wild.

In June, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following Ubiquiti UniFi OS issues to its Known Exploited Vulnerabilities (KEV) catalog.

  • CVE-2026-34910 Ubiquiti UniFi OS Improper Input Validation Vulnerability
  • CVE-2026-34908 Ubiquiti UniFi OS Improper Access Control Vulnerability
  • CVE-2026-34909 Ubiquiti UniFi OS Path Traversal Vulnerability

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

❌