CVE-2026-50746: Command Injection
Published Jul 2, 2026
·Updated
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.
Affected Software
2 affected components
Ubiquiti UniFi Connect Application
UI Unifi Connect Application<3.24.20
Event History
Jul 2, 2026
CVE Published
via MITRE·02:49 PM
Data Sourced
via MITRE·02:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeaknessAffected Software
Jul 8, 2026
News Published
via BleepingComputer·08:15 AM
News Published
via BleepingComputer·08:16 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-50746?
The severity of CVE-2026-50746 is critical with a score of 10.
2
What type of vulnerability is CVE-2026-50746?
CVE-2026-50746 is classified as an Improper Access Control vulnerability leading to Command Injection.
3
How can CVE-2026-50746 be exploited?
A malicious actor with network access can exploit CVE-2026-50746 to execute commands on the host device.
4
Which applications are affected by CVE-2026-50746?
CVE-2026-50746 affects the Ubiquiti UniFi Connect Application.
5
How do I fix CVE-2026-50746?
To fix CVE-2026-50746, ensure your Ubiquiti UniFi Connect Application is updated to the latest version provided by Ubiquiti.