CVE-2026-50746
published 2026-07-02CVE-2026-50746: A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command…
PriorityP273critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
1.69%
76.0th percentile
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ubiquiti_inc | unifi_connect_application | < 3.4.20 | 3.4.20 |
| ui | unifi_connect_application | < 3.24.20 | 3.24.20 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.
ghsa_unreviewed·2026-07-02
CVE-2026-50746 [CRITICAL] CWE-284 A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.
VulDB
Ubiquiti UniFi Connect Application up to 3.4.19 access control
vuldb·2026-07-02·CVSS 10.0
CVE-2026-50746 [CRITICAL] Ubiquiti UniFi Connect Application up to 3.4.19 access control
A vulnerability was found in Ubiquiti UniFi Connect Application up to 3.4.19 and classified as critical. Affected is an unknown function. Executing a manipulation can lead to improper access controls.
This vulnerability is handled as CVE-2026-50746. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
blogs_hackernews·2026-07-13
CVE-2026-50746 ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That's supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they don't file tickets.
That's the shape of this week. Trusted code turns on the people who installed it. Old bugs from last year are still landing because the fix sat in a queue too long. Fake installers, poisoned packages, systems left facing the open internet, and helpful little AI assistants running instructions that were
Hackernews
Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
blogs_hackernews·2026-07-08·CVSS 10.0
CVE-2026-50746 [CRITICAL] Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
Ubiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS that could result in privilege escalation and arbitrary command execution.
The list of vulnerabilities is as follows -
CVE-2026-50746 (CVSS score: 10.0) - An improper access control vulnerability in UniFi Connect Application that an attacker with access to the network could exploit to execute a command injection on the host device. (Affects versions 3.4.16 and earlier; fixed in version 3.4.20
2026-07-02
Published