Description
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.
Published: 2026-07-02
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

UniFi Connect Application has an Improper Access Control flaw (CWE‑284) that permits an attacker who can reach the application over the network to inject arbitrary shell commands. This flaw gives the attacker host‑level privileges, enabling code execution, data exfiltration, or persistence without user interaction.

Affected Systems

All installations of Ubiquiti Inc’s UniFi Connect Application may be affected. The CVE data does not list specific versions or builds, so any deployed instance could be vulnerable.

Risk and Exploitability

The vulnerability scores a CVSS of 10, signifying maximum severity, while the EPSS score of less than 1% suggests a low statistical likelihood of exploitation at present. It is not listed in CISA’s KEV catalog. The likely attack surface consists of any network endpoints that expose the UniFi Connect service without proper authorization checks, allowing a network‑connected actor to send crafted requests and trigger the command injection.

Generated by OpenCVE AI on July 21, 2026 at 11:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Ubiiti patch that closes the control flaw, as outlined in Security Advisory Bulletin 066.
  • Restrict network access to the UniFi Connect service so only authorized management IP addresses can reach it, using firewalls or network segmentation.
  • If the UniFi Connect service is not essential for your environment, uninstall or disable it to remove the attack surface.

Generated by OpenCVE AI on July 21, 2026 at 11:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in UniFi Connect Application

Wed, 15 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in UniFi Connect Application

Mon, 13 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Connect Application Allows Command Injection

Sun, 12 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Connect Application Allows Command Injection

Sat, 11 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in Ubiquiti UniFi Connect Application

Fri, 10 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in Ubiquiti UniFi Connect Application

Thu, 09 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control Leading to Command Injection in UniFi Connect Application

Wed, 08 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control Leading to Command Injection in UniFi Connect Application

Wed, 08 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in UniFi Connect Application

Mon, 06 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in UniFi Connect Application

Mon, 06 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in UniFi Connect

Mon, 06 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in UniFi Connect

Sun, 05 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Connect Allows Network-Based Host Command Injection

Sun, 05 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Connect Allows Network-Based Host Command Injection

Sat, 04 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in UniFi Connect

Sat, 04 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in UniFi Connect

Sat, 04 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Command Injection Vulnerability in Ubiquiti UniFi Connect Application Allowing Remote Code Execution

Fri, 03 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Command Injection Vulnerability in Ubiquiti UniFi Connect Application Allowing Remote Code Execution

Fri, 03 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in UniFi Connect

Thu, 02 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in UniFi Connect

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-02T15:52:15.315Z

Reserved: 2026-06-06T15:00:09.780Z

Link: CVE-2026-50746

cve-icon Vulnrichment

Updated: 2026-07-02T15:50:02.855Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:15:05Z

Weaknesses