CVE-2026-50748Patch(ui / unifi_access)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch ui unifi_access systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • unifi_access

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-07-03); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
unifi_access

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-07-02: 1Mentions · 2026-07-03: 2Mentions · 2026-08-03: 1Mentions · 2026-08-17: 1PoC Mentioned / Linked · 2026-08-17: 1Patch / Workaround · 2026-07-03: 2Patch / Workaround · 2026-08-03: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-03: 2Technical Details · 2026-08-03: 1Technical Details · 2026-08-17: 107-0207-0308-0308-17
Signal classification2 categories
Patch
360.0%
Disclosure
240.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-07-021
Disclosure1
2026-07-032
Patch2
2026-08-031
Patch1
2026-08-171
Disclosure1
Full discourse5 posts
  • I'M H4CK3R 42@luckyhacker43
    Disclosure

    $42,751 Ubiquiti Inc. Bug Bounty 🤑 Pre-Auth RCE in UniFi OS - CVE-2026-34909: One Request to Root Behind Seven Products by Catchify Security 🤯🔥 🔗 https://www.catchify.sa/post/pre-auth-rce-unifi-os-one-request-to-root CVEs 🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-34909 🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-50747 🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-50748 Join team 👉http://t.me/luckyhacker42

    Post summary

    The text announces a Pre‑Auth Remote Code Execution vulnerability (CVE‑2026‑34909) in Ubiquiti UniFi OS, provides a link to a PoC, but does not mention exploit tools, active attacks, patches, or a debunking claim.

    121017612320.2K
    4.7K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Ubiquiti UniFi Access Application Command Injection (CVE-2026-50748) An improper input validation flaw in Ubiquiti's UniFi Access Application lets a network-adjacent attacker with low privileges inject and execute arbitrary OS commands on the host device. Unvalidated input reaches a host command, turning a low-privileged foothold into command execution on the underlying appliance. Because UniFi Access governs physical door and entry hardware, code execution on the host can undermine both the device and the access control it enforces. The flaw is remotely exploitable with low complexity, requires only low privileges, and needs no user interaction (CVSS 9.9). 👉Upgrade to UniFi Access Application 4.2.29.

    Post summary

    The content announces a critical command‑injection flaw in Ubiquiti UniFi Access that allows remote code execution and recommends upgrading to version 4.2.29 to remediate the issue.

    00010123
    236 followersView on X
  • IntegSec@integ_sec
    Patch

    CVE-2026-50748: UniFi Access Application Command Injection - What It Means for Your Business and How to Respond https://hubs.li/Q04rHy8G0

    Post summary

    The article is a mitigation guide for the UniFi CVE-2026-50748 command injection vulnerability, focusing on patching and response steps rather than providing exploit code or evidence of active exploitation.

    0000048
    32 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    CVE-2026-50748 (CVSS 9.9) affects UniFi Access Application. Organizations using it should review the advisory and apply updates. http://adkcyber.com via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/FjXsLa7bbZ

    Post summary

    The tweet announces a high‑severity vulnerability in UniFi Access Application, urging users to review vendor advisories and apply available updates.

    0000043
    92 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-50748 Command Injection in UniFi Access Application via Improper Input Validation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-50748

    Post summary

    The entry announces a command injection vulnerability in the UniFi Access Application, but does not provide a PoC, exploit code, or information on active exploitation or patches.

    00000131
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appuiunifi_access---

Explore more