PT-2026-55231 · Ubiquiti · Unifi Connect

CVE-2026-50746

·

Published

2026-07-02

·

Updated

2026-07-10

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UniFi Connect Application versions prior to 3.4.17 UniFi Talk (affected versions not specified) UniFi Access (affected versions not specified) UniFi Protect (affected versions not specified) UniFi OS (affected versions not specified)
Description An improper access control flaw exists in the UniFi Connect Application that allows a malicious actor with network access to execute arbitrary commands on the host device without authentication. This issue can lead to privilege escalation and full control over managed environments, including building automation systems such as smart lighting, displays, and EV chargers.
Recommendations Update UniFi Connect Application to version 3.4.17 or later. Apply the latest security updates released by Ubiquiti for UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS. Restrict management access by using a VPN or jump host and avoid exposing administrative interfaces directly to the internet. Segment building automation and IoT networks to minimize the risk of lateral movement.

Fix

RCE

DoS

LPE

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50746

Affected Products

Unifi Connect