CVE-2026-50746

unifi_connect_application: Improper Access Control (CVE-2026-50746)

criticalPoCEPSS 1.7%

Affected

  • ui/unifi_connect_application lt *..3.24.20

Description

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

uiunifi_connect_application
3.24.20fixed from 3.24.20

Metrics

10.0
Source: nvd-v3
76.4 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
PoC (publicly reported)
1.7 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-07-02 15:17 UTC
CWE-284

Weakness classes (CWE)

  • CWE-284Pillar

    Improper Access Control

    The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Initial Analysis2026-07-09 13:22 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:ui:unifi_connect_application:*:*:*:*:*:*:*:* versions up to (excluding) 3.4.20
    • Reference Type: HackerOne: https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc Types: Vendor Advisory
  2. CVE Modified2026-07-02 16:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-50746","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
  3. New CVE Received2026-07-02 15:17 UTC· support@hackerone.com
    • Affected: UniFi Connect Application
    • Description: A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    • CWE: CWE-284

Linked advisories