CVE-2026-50747
Summary
A SQL-injection vulnerability in Ubiquiti UniFi Talk, scored CVSS 9.9, patched in Ubiquiti's July 2026 UniFi updates.
Details
Part of the same UniFi release as the UniFi Connect command injection (CVE-2026-50746, CVSS 10.0) and the UniFi Access input-validation flaw (CVE-2026-50748, CVSS 9.9). SQL injection in a telephony service is a data-and-authentication problem rather than a signalling one — the database holds account and call metadata rather than media — but the deployment context is what raises it: these controllers are usually reachable from the management VLAN and often from the internet for remote administration, which is where a CVSS 9.9 stops being theoretical. Patch as part of the family, not individually.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-50747 |
| CVSS | 9.9 |
| Vendor / product | Ubiquiti (UniFi Talk) |
| Reported in the digest | 2026-07-09 |
Related Pages
- Cve 2026 50746 · Cve 2026 50748 (same UniFi release)
- Source article
Sources: raw/digests/Cyber-Digest-2026-07-09.md