type: cve · created: 2026-09-23 · updated: 2026-09-23 · tags: [cve] · confidence: high · severity: critical · affected_sectors: [technology, retail] · au_impact: false
CVE-2026-50748
Summary
An input-validation vulnerability in Ubiquiti UniFi Access, scored CVSS 9.9, patched in Ubiquiti's July 2026 UniFi updates.
Details
UniFi Access controls door controllers and badge readers, so a flaw in its input handling sits on the boundary between the IT network and physical access — the combination that makes controller compromises consequential rather than merely inconvenient. The digest recorded it in the same three-flaw UniFi release as CVE-2026-50746 and CVE-2026-50747, neither of which carried exploitation evidence; the family should be patched together because the products share a management interface.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-50748 |
| CVSS | 9.9 |
| Vendor / product | Ubiquiti (UniFi Access) |
| Reported in the digest | 2026-07-09 |
Related Pages
- Cve 2026 50746 · Cve 2026 50747 (same UniFi release)
- Source article
Sources: raw/digests/Cyber-Digest-2026-07-09.md