Description
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.
Published: 2026-07-02
Score: 10 Critical
EPSS: 2.5% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

UniFi Connect Application has an Improper Access Control flaw (CWE‑284) that allows an attacker who can reach the application over the network to inject arbitrary shell commands. This gives host‑level code execution capability, enabling the attacker to exfiltrate data, modify configuration, or establish persistence without user interaction.

Affected Systems

All deployments of Ubiquiti Inc’s UniFi Connect Application may be affected. No specific product versions are listed, so any instance could be vulnerable until the vendor releases a patch.

Risk and Exploitability

The CVSS score of 10 indicates maximum severity, while the EPSS score of 3% suggests a moderate probability of exploitation. Based on the description, the likely attack vector is network connectivity to the UniFi Connect service with no authentication requirement, making the vulnerability highly exploitable in environments that expose the service. The vulnerability is not listed in CISA KEV, but its high severity warrants immediate remediation.

Generated by OpenCVE AI on August 4, 2026 at 18:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch released in Security Advisory Bulletin 066 to fix the improper access control flaw.
  • Restrict network access to the UniFi Connect service so only authorized management IP addresses can reach it, using firewalls or network segmentation.
  • If the UniFi Connect service is not essential, disable or uninstall it to remove the attack surface.

Generated by OpenCVE AI on August 4, 2026 at 18:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Network Access Enables Command Injection in Ubiquiti UniFi Connect Application

Fri, 31 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Network Access Enables Command Injection in Ubiquiti UniFi Connect Application

Sun, 26 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in Ubiquiti UniFi Connect

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in Ubiquiti UniFi Connect

Tue, 21 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in UniFi Connect Application

Wed, 15 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in UniFi Connect Application

Mon, 13 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Connect Application Allows Command Injection

Sun, 12 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Connect Application Allows Command Injection

Sat, 11 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in Ubiquiti UniFi Connect Application

Fri, 10 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in Ubiquiti UniFi Connect Application

Thu, 09 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control Leading to Command Injection in UniFi Connect Application

Wed, 08 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control Leading to Command Injection in UniFi Connect Application

Wed, 08 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in UniFi Connect Application

Mon, 06 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in UniFi Connect Application

Mon, 06 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in UniFi Connect

Mon, 06 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in UniFi Connect

Sun, 05 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Connect Allows Network-Based Host Command Injection

Sun, 05 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in UniFi Connect Allows Network-Based Host Command Injection

Sat, 04 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in UniFi Connect

Sat, 04 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in UniFi Connect

Sat, 04 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Command Injection Vulnerability in Ubiquiti UniFi Connect Application Allowing Remote Code Execution

Fri, 03 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Command Injection Vulnerability in Ubiquiti UniFi Connect Application Allowing Remote Code Execution

Fri, 03 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in UniFi Connect

Thu, 02 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Access Control in UniFi Connect

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ui Unifi Connect Application
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-02T15:52:15.315Z

Reserved: 2026-06-06T15:00:09.780Z

Link: CVE-2026-50746

cve-icon Vulnrichment

Updated: 2026-07-02T15:50:02.855Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-02T15:17:02.723

Modified: 2026-07-29T19:16:06.857

Link: CVE-2026-50746

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T19:00:10Z

Weaknesses