Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-09-23 · updated: 2026-09-23 · tags: [cve] · confidence: high · severity: critical · affected_sectors: [technology, retail] · au_impact: false

CVE-2026-50747

Summary

A SQL-injection vulnerability in Ubiquiti UniFi Talk, scored CVSS 9.9, patched in Ubiquiti's July 2026 UniFi updates.

Details

Part of the same UniFi release as the UniFi Connect command injection (CVE-2026-50746, CVSS 10.0) and the UniFi Access input-validation flaw (CVE-2026-50748, CVSS 9.9). SQL injection in a telephony service is a data-and-authentication problem rather than a signalling one — the database holds account and call metadata rather than media — but the deployment context is what raises it: these controllers are usually reachable from the management VLAN and often from the internet for remote administration, which is where a CVSS 9.9 stops being theoretical. Patch as part of the family, not individually.

Attribute Detail
CVE CVE-2026-50747
CVSS 9.9
Vendor / product Ubiquiti (UniFi Talk)
Reported in the digest 2026-07-09

Related Pages

Sources: raw/digests/Cyber-Digest-2026-07-09.md