---
schema: 1
kind: vulnerability
title: "Ubiquiti UniFi SAB-066 — 25 vulnerabilities incl. unauthenticated CVSS 10.0 command injection in UniFi Connect (CVE-2026-50746)"
headline: "NCSC-NL flags Ubiquiti UniFi SAB-066: unauthenticated CVSS 10.0 command injection plus 24 more"
summary: >
  NCSC-NL advisory NCSC-2026-0221 covers Ubiquiti's Security Advisory Bulletin 066 — 25 vulnerabilities across UniFi Connect, Talk, Access, Network, Protect and UniFi OS. The headline flaw CVE-2026-50746 (CVSS 10.0) is unauthenticated command injection in UniFi Connect; a chainable path-traversal auth-bypass (CVE-2026-54403) removes the privilege prerequisite for others. No exploitation yet; upgrade-only, no interim mitigations.
discovered_at: "2026-07-08T20:35:00Z"
event_date: 2026-07-07
run_id: 2026-07-08T2009Z-intel
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - pre-auth
  - patch-available
  - auth-bypass
  - path-traversal
  - sqli
regions:
  - global
  - europe
sectors:
  - public-sector
  - telco
entities: []
cves:
  - id: CVE-2026-50746
    cvss: "10.0"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
    affected: "UniFi Connect Application < 3.4.20"
    fixed: "3.4.20"
  - id: CVE-2026-50747
    cvss: "9.9"
    epss: null
    type: sqli
    vector: zero-click
    auth: post-auth
    status:
      - patch-available
    affected: "UniFi Talk < 5.2.2"
    fixed: "5.2.2"
  - id: CVE-2026-50748
    cvss: "9.9"
    epss: null
    type: rce
    vector: zero-click
    auth: post-auth
    status:
      - patch-available
    affected: "UniFi Access < 4.2.29"
    fixed: "4.2.29"
  - id: CVE-2026-54402
    cvss: "9.9"
    epss: null
    type: rce
    vector: zero-click
    auth: post-auth
    status:
      - patch-available
    affected: "UniFi OS < 5.1.19"
    fixed: "5.1.19"
  - id: CVE-2026-54403
    cvss: "8.6"
    epss: null
    type: path-traversal
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
    affected: "UniFi OS < 5.1.19"
    fixed: "5.1.19"
  - id: CVE-2026-55115
    cvss: "9.9"
    epss: null
    type: ssrf
    vector: zero-click
    auth: post-auth
    status:
      - patch-available
    affected: "UniFi Protect < 7.1.83"
    fixed: "7.1.83"
sources:
  - url: "https://advisories.ncsc.nl/advisory?id=NCSC-2026-0221"
    publisher: "NCSC Netherlands"
    date: "2026-07-07"
    role: primary
  - url: "https://socradar.io/blog/ubiquiti-cve-2026-50746-unifi-connect/"
    publisher: "SOCRadar"
    date: "2026-07-08"
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification: null
watchlist_hit: false
actions:
  - "Update UniFi Connect ≥ 3.4.20, Talk ≥ 5.2.2, Access ≥ 4.2.29, Protect ≥ 7.1.83 and UniFi OS ≥ 5.1.19; no interim mitigation is documented for any of the 25 CVEs."
  - "Segregate every UniFi management-plane interface (controller UI, Connect, Talk, Access) from general LAN/internet exposure regardless of patch state — several flaws need only network adjacency and no or low privilege."
migrated_from: null
---

NCSC-NL published advisory NCSC-2026-0221 on 7 July 2026 covering Ubiquiti's Security Advisory Bulletin 066 (vendor-published 2026-07-02): 25 vulnerabilities spanning the UniFi Connect, Talk, Access, Network and Protect applications plus the UniFi OS platform itself across the Dream Machine / Cloud Gateway / Cloud Key / Network-Video-Recorder / Enterprise-Fortress-Gateway hardware families ([NCSC-NL, 2026-07-07](https://advisories.ncsc.nl/advisory?id=NCSC-2026-0221)). This is a distinct, larger disclosure from the CVE-2026-34908/-34909/-34910 UniFi OS chain covered on 2026-06-24 — different CVEs, broader scope. The most severe, CVE-2026-50746 (CVSS 10.0), is an improper-access-control flaw in UniFi Connect (< 3.4.20) letting a network-adjacent unauthenticated attacker execute OS command injection on the host device; CVE-2026-50747 (CVSS 9.9, authenticated SQLi in Talk), CVE-2026-50748 (CVSS 9.9, command injection in Access), CVE-2026-54402 (CVSS 9.9, command injection in UniFi OS) and CVE-2026-55115 (CVSS 9.9, SSRF in Protect) round out the critical set, and CVE-2026-54403 (CVSS 8.6, path traversal in UniFi OS) bypasses authentication outright and is explicitly flagged by Ubiquiti as chainable to drop the low-privilege prerequisite of the others. SOCRadar confirms no functional public PoC and no confirmed in-the-wild exploitation as of 2026-07-08 ([SOCRadar, 2026-07-08](https://socradar.io/blog/ubiquiti-cve-2026-50746-unifi-connect/)). **Defender takeaway:** UniFi gear is dense across DACH/EU schools, municipal government and SME networks, and the June UniFi disclosure showed the platform is actively targeted once exposed; there is no interim mitigation for any of the 25 flaws, so the operational move is to patch the affected applications/OS and, independent of patch state, pull every UniFi management interface off internet/WAN exposure and watch UniFi Protect hosts for SSRF-style outbound probing of internal service endpoints.
