Recent Unifi OS updates - CVEs listed in body

In regard to a recent article on TheHackerNews Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS

block quote:

The list of vulnerabilities is as follows -

  • CVE-2026-50746 (CVSS score: 10.0) - An improper access control vulnerability in UniFi Connect Application that an attacker with access to the network could exploit to execute a command injection on the host device. (Affects versions 3.4.16 and earlier; fixed in version 3.4.20)
  • CVE-2026-50747 (CVSS score: 9.9) - A series of authenticated SQL injection vulnerabilities in UniFi Talk Application that an attacker with access to the network could exploit to escalate privileges on the host device. (Affects versions 5.1.2 and earlier; fixed in version 5.2.2)
  • CVE-2026-50748 (CVSS score: 9.9) - An improper input validation vulnerability in UniFi Access Application that an attacker with access to the network could exploit to execute a command injection on the host device. (Affects versions 4.2.28 and earlier; fixed in version 4.2.29)
  • CVE-2026-54400 (CVSS score: 9.1) - An improper access control vulnerability in UniFi Access Application that an attacker with access to the network could exploit to escalate privileges on the host device. (Affects versions 4.2.28 and earlier; fixed in version 4.2.29)
  • CVE-2026-55115 (CVSS score: 9.9) - A Server-Side Request Forgery (SSRF) vulnerability in UniFi Protect Application that an attacker with access to the network and low privileges could exploit to escalate privileges on the host device. (Affects 7.1.77 and earlier; fixed in version 7.1.83)
  • CVE-2026-54402 (CVSS score: 9.9) - An improper input validation vulnerability in UniFi OS that an attacker with access to the network could exploit to execute a command injection on the host device. (Affects versions 5.1.15 and earlier; fixed in version 5.1.19)
  • CVE-2026-55116 (CVSS score: 9.0) - An improper access control vulnerability in UniFi OS that an attacker with access to the network could exploit to make unauthorized changes to certain devices. (Affects versions 5.1.15 and earlier; fixed in version 5.1.19)

Might the severity and breadth of the patched vulnerabilities seems to be large enough to be worthy of a quick video reminding users to enable auto-updates and to check to see that updates are being applied on a regular basis?

This topic has been covered in the UI support portal here:

https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc

Bug bounty program working as expected and happy to see it still in place as the AI tools have really ramped up the discovery. UniFi has paid out over $200K in the past 90 days. They pay much better than other networking vendors in the space. HackerOne

3 Likes

Hi, Yes, Its worth covering!

It’s so clear patching is the only mitigation and there are huge risks for internet-exposed consoles. So here we need to give immediate attention to the CVSS 10.0 unauthenticated vulnerability with 25 disclosed CVEs.

And when it comes to the video, it’s better to focus on the urgency than fear. Have a flow something like check updates, enable automatic updates and then verify your UniFi OS version.

Why is anyone exposing their console to the internet? If someone is doing that then they don’t need to be managing a firewall.

1 Like

Yeah, exposing management interfaces is a huge problem not just with UniFi but with many other firewalls. Some of the issues with Fortigate, Palo Alto, and others would have had much less impact if they were not exposed to the public internet.