CVE-2026-50746: Critical Unauthenticated Command Injection in Ubiquiti UniFi Connect Application (CVSS 10.0) — Threadlinqs Intelligence
As of 2026-07-18, CVE-2026-50746: Critical Unauthenticated Command Injection in Ubiquiti UniFi Connect Application (CVSS 10.0) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-1159 · Severity: CRITICAL · CVSS: 10 · Status: PATCHED · Category: VULNERABILITY
Updated: 2026-07-18 · revalidated 1× · latest source
Ubiquiti's UniFi Connect Application versions 3.4.16 and earlier contain a maximum-severity (CVSS 10.0) improper access control flaw (CWE-284) that allows a network-adjacent, unauthenticated attacker
CVE-2026-50746 is an improper access control vulnerability (CWE-284) in the UniFi Connect Application, the Ubiquiti software suite used to manage commercial building automation systems — including smart LED lighting and electric vehicle (EV) charging infrastructure — through a unified web interface. The flaw exposes internal functionality that should be access-restricted, allowing a malicious actor with only network reachability to the service (no authentication, no privileges, no user interaction) to inject and execute arbitrary operating-system commands on the host running UniFi Connect.
The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) reflects the worst-case combination for an internet/network-exposed management product: network attack vector, low attack complexity, no privileges required, no user interaction, a scope change (the vulnerable component impacts resources beyond its own security scope — consistent with host-level command execution from an application-layer flaw), and complete loss of confidentiality, integrity, and availability. This combination yields the maximum possible base score of 10.0.
The vulnerability was disclosed by Ubiquiti on 2026-07-02 (NVD publish date) as part of Security Advisory Bulletin 066 (SAB-066), a coordinated disclosure covering 25 vulnerabilities across the UniFi product ecosystem (Connect, Talk, Access, Protect, Network Application, and core UniFi OS on UDM/UNVR/UNAS hardware). CVE-2026-50746 was the single most severe finding in that bulletin. Six other critical-tier vulnerabilities were patched in the same release cycle: CVE-2026-50747 (9.9, authenticated SQL injection in UniFi Talk), CVE-2026-50748 (9.9, command injection / input validation bypass in UniFi Access), CVE-2026-54400 (9.1, privilege escalation in UniFi Access), CVE-2026-54402 (9.9, command injection/SSRF affecting UniFi OS on UDM/UNVR/UNAS hardware), CVE-2026-55115 (9.9, SSRF-driven privilege escalation / CORS misconfiguration in UniFi Protect), and CVE-2026-55116 (9.0, improper access control enabling unauthorized configuration changes on UDM gateway devices). Ubiquiti also disclosed CVE-2026-54403 (8.6, path traversal), explicitly noted as chainable with other SAB-066 flaws to bypass authentication entirely — illustrating that several of these issues were designed to be exploited together in a single intrusion chain rather than in isolation.
As of publication, no functional public proof-of-concept exploit is known and Ubiquiti has not disclosed evidence of active exploitation; CISA's ADP/SSVC assessment for CVE-2026-50746 records exploitation status as "none." However, exposure research cited by multiple outlets found more than 100,000 UniFi OS instances reachable on the public internet (roughly 50,000 in the United States alone), and Ubiquiti's own advisory states no interim workarounds exist for any of the 25 SAB-066 findings — firmware/application updates are the only mitigation. This threat is also notable because CISA's KEV catalog already lists three prior UniFi OS vulnerabilities exploited in the wild (CVE-2026-34908 improper access control, CVE-2026-34909 path traversal, CVE-2026-34910 command injection, all added to KEV 2026-06-23), establishing a documented pattern of real-world attacker interest in this exact vulnerability class (unauthenticated command injection / access-control bypass) against UniFi OS-family products just weeks before SAB-066. Defenders should treat CVE-2026-50746 as a high-priority patching target given this precedent, the perfect CVSS score, and the scale of internet-facing exposure, even absent a confirmed public exploit at this time.
Weaknesses (CWE)
CWE-284, CWE-89, CWE-22, CWE-918, CWE-346, CWE-77, CWE-78, CWE-362
Target sectors: commercialrealestate, smartbuildingautomation, hospitality, retail, criticalinfrastructureadjacent, smallmediumbusiness, managedserviceproviders
Target regions: North America, Europe, Global
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-50746, CVE-2026-50747, CVE-2026-50748, CVE-2026-54400, CVE-2026-54402, CVE-2026-54403, CVE-2026-55115, CVE-2026-55116, CVE-2026-34908, CVE-2026-34909, T1595.001, T1590.004, T1587.004, T1190, T1059, T1059.004, T1203, T1505.003, T1136.001, T1068