CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Ubiquiti UniFi Talk authenticated SQL injection (CVSS 9.9), SAB-066

cve · CVE-2026-50747

Coverage
1
first 2026-07-08 → last 2026-07-08
Latest activity
2026-07-08
NCSC-NL flags Ubiquiti UniFi SAB-066: unauthenticated CVSS 10.0 command injection plus 24 more
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, telco · regions: europe
Sources cited
2
2 hosts

Action items (2)

Do-now tasks recorded on the entries about CVE-2026-50747, newest first. Check the date before acting on an older one.

  • Update UniFi Connect ≥ 3.4.20, Talk ≥ 5.2.2, Access ≥ 4.2.29, Protect ≥ 7.1.83 and UniFi OS ≥ 5.1.19; no interim mitigation is documented for any of the 25 CVEs.
    2026-07-08CVE-2026-50746 +5
  • Segregate every UniFi management-plane interface (controller UI, Connect, Talk, Access) from general LAN/internet exposure regardless of patch state; several flaws need only network adjacency and no or low privilege.
    2026-07-08CVE-2026-50746 +5

Defender insights

What each entry about CVE-2026-50747 tells a defender to do, newest first.

2026-07-08NOTABLENCSC-NL flags Ubiquiti UniFi SAB-066: unauthenticated CVSS 10.0 command injection plus 24 more

Story timeline

  1. 2026-07-08Ubiquiti UniFi SAB-066, 25 vulnerabilities incl. unauthenticated CVSS 10.0 command injection in UniFi Connect (CVE-2026-50746)
    trending-vulnerabilitiesNCSC-NL flags Ubiquiti UniFi SAB-066: unauthenticated CVSS 10.0 command injection plus 24 more

Entries about Ubiquiti UniFi Talk authenticated SQL injection (CVSS 9.9), SAB-066 (1)

2026-07-08 · view entry permalink →

Ubiquiti UniFi SAB-066, 25 vulnerabilities incl. unauthenticated CVSS 10.0 command injection in UniFi Connect (CVE-2026-50746)

NCSC-NL published advisory NCSC-2026-0221 on 7 July 2026 covering Ubiquiti's Security Advisory Bulletin 066 (vendor-published 2026-07-02): 25 vulnerabilities spanning the UniFi Connect, Talk, Access, Network and Protect applications plus the UniFi OS platform itself across the Dream Machine / Cloud Gateway / Cloud Key / Network-Video-Recorder / Enterprise-Fortress-Gateway hardware families (NCSC-NL, 2026-07-07). This is a distinct, larger disclosure from the CVE-2026-34908/-34909/-34910 UniFi OS chain covered on 2026-06-24, different CVEs, broader scope. The most severe, CVE-2026-50746 (CVSS 10.0), is an improper-access-control flaw in UniFi Connect (< 3.4.20) letting a network-adjacent unauthenticated attacker execute OS command injection on the host device; CVE-2026-50747 (CVSS 9.9, authenticated SQLi in Talk), CVE-2026-50748 (CVSS 9.9, command injection in Access), CVE-2026-54402 (CVSS 9.9, command injection in UniFi OS) and CVE-2026-55115 (CVSS 9.9, SSRF in Protect) round out the critical set, and CVE-2026-54403 (CVSS 8.6, path traversal in UniFi OS) bypasses authentication outright and is explicitly flagged by Ubiquiti as chainable to drop the low-privilege prerequisite of the others. SOCRadar confirms no functional public PoC and no confirmed in-the-wild exploitation as of 2026-07-08 (SOCRadar, 2026-07-08).

vulnerability08 Jul 20:35Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • advisories.ncsc.nl1 (50%)
  • socradar.io1 (50%)