PT-2026-55231 · Ubiquiti · Unifi Connect
CVE-2026-50746
·
Published
2026-07-02
·
Updated
2026-07-10
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UniFi Connect Application versions prior to 3.4.17
UniFi Talk (affected versions not specified)
UniFi Access (affected versions not specified)
UniFi Protect (affected versions not specified)
UniFi OS (affected versions not specified)
Description
An improper access control flaw exists in the UniFi Connect Application that allows a malicious actor with network access to execute arbitrary commands on the host device without authentication. This issue can lead to privilege escalation and full control over managed environments, including building automation systems such as smart lighting, displays, and EV chargers.
Recommendations
Update UniFi Connect Application to version 3.4.17 or later.
Apply the latest security updates released by Ubiquiti for UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS.
Restrict management access by using a VPN or jump host and avoid exposing administrative interfaces directly to the internet.
Segment building automation and IoT networks to minimize the risk of lateral movement.
Fix
RCE
DoS
LPE
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unifi Connect