top of page
perceptive_background_267k.jpg

Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS

Published:

8 juli 2026 om 14:38:05

Alert date:

8 juli 2026 om 15:06:43

Source:

thehackernews.com

Click to open the original link from this advisory

Network Infrastructure, Mobile & IoT, Zero-Day Vulnerabilities, Identity & Access

Ubiquiti has released security updates addressing multiple critical vulnerabilities across its UniFi product lineup, including UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS. The most severe flaw, CVE-2026-50746, carries a perfect CVSS score of 10.0 and involves an improper access control vulnerability in the UniFi Connect Application. The vulnerabilities could allow attackers to perform privilege escalation and execute arbitrary commands on affected systems. The breadth of affected products suggests a wide potential attack surface across Ubiquiti's networking and security ecosystem. Users are strongly advised to apply the available patches immediately to mitigate potential exploitation risks.

Technical details

Ubiquiti disclosed and patched seven critical-to-high severity vulnerabilities across multiple UniFi product lines. CVE-2026-50746 (CVSS 10.0) is an improper access control flaw in UniFi Connect Application allowing network-accessible attackers to perform command injection on the host device. CVE-2026-50747 (CVSS 9.9) involves authenticated SQL injection vulnerabilities in UniFi Talk Application enabling privilege escalation. CVE-2026-50748 (CVSS 9.9) is an improper input validation flaw in UniFi Access Application enabling command injection. CVE-2026-54400 (CVSS 9.1) is an improper access control vulnerability in UniFi Access Application allowing privilege escalation. CVE-2026-55115 (CVSS 9.9) is a Server-Side Request Forgery (SSRF) vulnerability in UniFi Protect Application exploitable by low-privileged network-adjacent attackers to escalate privileges. CVE-2026-54402 (CVSS 9.9) is an improper input validation vulnerability in UniFi OS enabling command injection. CVE-2026-55116 (CVSS 9.0) is an improper access control vulnerability in UniFi OS allowing unauthorized device configuration changes. No in-the-wild exploitation of these specific CVEs has been confirmed, however, three separate UniFi OS vulnerabilities (CVE-2026-34908, CVE-2026-34909, CVE-2026-34910) were previously flagged by CISA as actively exploited. Additionally, Russian state-sponsored actors were previously observed using compromised Ubiquiti Edge OS routers in the MooBot botnet to proxy malicious traffic, disrupted by law enforcement in February 2024.

Mitigation steps:

Update all affected Ubiquiti UniFi products to their respective patched versions immediately: UniFi Connect Application to version 3.4.20 or later; UniFi Talk Application to version 5.2.2 or later; UniFi Access Application to version 4.2.29 or later; UniFi Protect Application to version 7.1.83 or later; UniFi OS to version 5.1.19 or later. Restrict network access to UniFi management interfaces where possible. Monitor for unauthorized privilege escalation, unexpected command execution, and unusual configuration changes on UniFi devices. Review CISA advisories for previously exploited UniFi OS vulnerabilities (CVE-2026-34908, CVE-2026-34909, CVE-2026-34910) and ensure those are also remediated. Audit Ubiquiti Edge OS routers for signs of compromise or enrollment in botnets such as MooBot.

Affected products:

UniFi Connect Application versions 3.4.16 and earlier (fixed in 3.4.20)
UniFi Talk Application versions 5.1.2 and earlier (fixed in 5.2.2)
UniFi Access Application versions 4.2.28 and earlier (fixed in 4.2.29)
UniFi Protect Application versions 7.1.77 and earlier (fixed in 7.1.83)
UniFi OS versions 5.1.15 and earlier (fixed in 5.1.19)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page