Junglewise Threat Intelligence

CVE-2026-50746: Ubiquiti UniFi Connect command injection via improper access control

CVE-2026-50746 · Severity: critical · CVSS 10 · Published 2026-07-02

Vendors: Ubiquiti Inc.

Executive brief

Ubiquiti UniFi Connect, an application used to manage and deploy digital signage and smart building devices, contains a critical security flaw. An attacker with network access can bypass security controls to take full control of the host device. This could lead to a complete compromise of the management system, unauthorized access to connected devices, and the potential for data theft or service disruption.

Technical details

An improper access control vulnerability (CWE-284) exists in the Ubiquiti UniFi Connect Application prior to version 3.4.20. The flaw allows an unauthenticated attacker with network access to bypass authorization mechanisms and achieve command injection on the underlying host operating system. Given the CVSS score of 10.0 and the 'Scope: Changed' metric, an exploit could lead to full system compromise and lateral movement within the network. Users are advised to update the UniFi Connect Application to version 3.4.20 or later to mitigate this risk.

Affected products

  • Ubiquiti Inc UniFi Connect Application < 3.4.20

Timeline

  • 2026-07-02: advisory: Security Advisory Bulletin 066 published by Ubiquiti
  • 2026-07-02: disclosed: CVE-2026-50746 published to NVD

References