CVE-2026-50747: SQL Injection
Published Jul 2, 2026
·Updated
A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device.
Affected Software
2 affected components
UniFi Talk Application
UI Unifi Talk Application<5.2.2
Event History
Jul 2, 2026
CVE Published
via MITRE·02:49 PM
Data Sourced
via MITRE·02:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeaknessAffected Software
Jul 8, 2026
News Published
via BleepingComputer·08:15 AM
News Published
via BleepingComputer·08:16 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-50747?
CVE-2026-50747 has a critical severity rating of 9.9.
2
What are the risk factors associated with CVE-2026-50747?
The risk factors include the potential for a malicious actor with network access and low privileges to exploit SQL Injection vulnerabilities.
3
How do I fix CVE-2026-50747?
To fix CVE-2026-50747, you should update the UniFi Talk Application to the latest version that addresses these vulnerabilities.
4
What type of vulnerability is CVE-2026-50747?
CVE-2026-50747 is classified as an SQL Injection vulnerability.
5
Who is affected by CVE-2026-50747?
Users of the UniFi Talk Application who have network access and low privileges are affected by CVE-2026-50747.