Cyber Cookie mascotCyber Cookie
Menu ▾
CVE-2026-50746
criticalCVSS 10

UniFi Connect Application (versions 3.4.16 and below)

UniFi Connect is a Ubiquiti platform for managing displays, intercom systems, and building access hardware — popular in small offices, schools, and home setups.

Reported in Issue #31KDDI Breach Hits 12 Million Email Accounts

Root Cause

The application does not enforce access controls before processing certain commands. A network-adjacent attacker can send a crafted request that the device treats as a trusted instruction, then execute commands at the system level. There is no authentication barrier in the way.

Attack Vector

An attacker on the local network sends a specially crafted request to the UniFi Connect service. The device processes it without checking who sent it, executes the embedded command, and hands the attacker control of the host. No credentials needed.

Recommended Actions

  1. Update UniFi Connect Application to version 3.4.20 or later immediately.
  2. Restrict network access to UniFi management interfaces to trusted devices only.
  3. Review other UniFi products in your environment — Ubiquiti patched six additional critical flaws across UniFi Talk, Access, Protect, and OS in the same release cycle.