top of page
perceptive_background_267k.jpg

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to ex…

Published:

1 juli 2026 om 22:00:00

Alert date:

2 juli 2026 om 17:05:12

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Mobile & IoT, Identity & Access

A high-severity vulnerability (CVE-2026-50748) has been identified in the UniFi Access Application. The flaw stems from Improper Input Validation, allowing a malicious actor with low privileges and network access to exploit a Command Injection weakness. Successful exploitation enables the attacker to execute arbitrary commands on the host device. The vulnerability poses significant risk to organizations using UniFi Access for physical access control management. Ubiquiti has published a Security Advisory Bulletin (066) addressing this issue. The low privilege requirement lowers the barrier for exploitation, making this a critical concern for network administrators. Patching or mitigating the vulnerability promptly is strongly recommended.

Technical details

Mitigation steps:

Affected products:

UniFi Access Application

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page