Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-09-23 · updated: 2026-09-23 · tags: [cve] · confidence: high · severity: critical · affected_sectors: [technology, retail] · au_impact: false

CVE-2026-50746

Summary

A command-injection vulnerability in Ubiquiti UniFi Connect, scored CVSS 10.0, patched in Ubiquiti's July 2026 UniFi updates.

Details

UniFi Connect drives digital signage and display control, so the practical concern is the network position rather than the function: these devices are managed from the same UniFi console as the access points and switches, and a command-injection flaw in a managed endpoint is a route into the management plane that governs the rest of the estate. The digest recorded it alongside two siblings in the same release — a SQL injection in UniFi Talk (CVE-2026-50747, CVSS 9.9) and an input-validation flaw in UniFi Access (CVE-2026-50748, CVSS 9.9) — which together describe a single product family patched in one cycle. None carried exploitation evidence at the time.

Attribute Detail
CVE CVE-2026-50746
CVSS 10.0
Vendor / product Ubiquiti (UniFi Connect)
Reported in the digest 2026-07-09

Related Pages

Sources: raw/digests/Cyber-Digest-2026-07-09.md