CVE-2026-50747Disclosure(ui / unifi_talk_application)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch ui unifi_talk_application systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • unifi_talk_application

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-07-02); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
unifi_talk_application

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-07-02: 1Mentions · 2026-07-03: 1Mentions · 2026-07-20: 1Mentions · 2026-08-03: 1Mentions · 2026-08-17: 1PoC Mentioned / Linked · 2026-08-17: 1Patch / Workaround · 2026-07-03: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-03: 1Technical Details · 2026-08-03: 1Technical Details · 2026-08-17: 107-0207-0307-2008-0308-17
Signal classification3 categories
Disclosure
360.0%
General
120.0%
PoC
120.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-07-021
Disclosure1
2026-07-031
Disclosure1
2026-07-201
General1
2026-08-031
Disclosure1
2026-08-171
PoC1
Full discourse5 posts
  • I'M H4CK3R 42@luckyhacker43
    PoC

    $42,751 Ubiquiti Inc. Bug Bounty 🤑 Pre-Auth RCE in UniFi OS - CVE-2026-34909: One Request to Root Behind Seven Products by Catchify Security 🤯🔥 🔗 https://www.catchify.sa/post/pre-auth-rce-unifi-os-one-request-to-root CVEs 🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-34909 🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-50747 🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-50748 Join team 👉http://t.me/luckyhacker42

    Post summary

    A pre‑authentication remote code execution vulnerability (CVE-2026-34909) in UniFi OS is disclosed with a claim that a proof‑of‑concept exists, but no active exploitation or patch information is provided.

    121017612320.2K
    4.7K followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-50747: UniFi Talk Application SQL Injection Privilege Escalation - What It Means for Your Business and How to Respond https://hubs.li/Q04rF3FC0

    Post summary

    The article announces CVE-2026-50747, a SQL injection-based privilege escalation in UniFi Talk, and discusses its business impact and recommended response steps.

    0000051
    32 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Ubiquiti ❗ CVE-2026-54402 ❗ CVE-2026-50747 ❗ CVE-2026-50746 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-ubiquiti-5/ https://t.co/X2hc3s6LUX

    Post summary

    The post lists several CVEs affecting Ubiquiti products and directs readers to external links for more information, but provides no further technical or exploit details.

    00000174
    6.7K followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    CVE-2026-50747 (CVSS 9.9) impacts UniFi Talk via authenticated SQL injection allowing privilege escalation. Review updates if your environment uses it. http://adkcyber.com via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/2Dve7GhQxn

    Post summary

    CVE-2026-50747 is a high‑severity authenticated SQL injection in UniFi Talk (CVSS 9.9) that can lead to privilege escalation; users should update their environment.

    0000046
    92 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-50747 Authenticated SQL Injection in UniFi Talk Application Leading to Privilege Escalation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-50747

    Post summary

    A newly disclosed authenticated SQL injection in the UniFi Talk application can lead to privilege escalation.

    00000111
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appuiunifi_talk_application---

Explore more