Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-50746 -- CVSS 10.0 Vulnerability Briefing

CVE-2026-50746 | CVSS 10.0 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-50746 is a critical improper access control vulnerability in the Ubiquiti UniFi Connect Application that allows a network-adjacent attacker to perform command injection on the underlying host device.

Technical Detail

The flaw stems from insufficient access controls within the UniFi Connect Application, which fails to properly validate or restrict user-supplied input before passing it to system-level command execution functions. An attacker with network access to the application can craft malicious input to inject arbitrary operating system commands, resulting in unauthenticated or low-privilege remote code execution on the host device. The CVSS score of 10.0 reflects the combination of network accessibility, no required authentication, and full system compromise potential.

Exploitation Status

No known exploit code has been publicly observed or confirmed as of July 09, 2026. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. While no active exploitation has been documented, the critical severity and network-accessible attack vector make this a high-priority target for threat actors conducting opportunistic scanning.

Who Is Targeting This

No specific threat actor attribution at this time. No confirmed or reported threat actor activity has been associated with this CVE as of the date of this briefing.

What To Do

Apply the vendor-supplied patch for the UniFi Connect Application immediately, prioritizing any internet-facing or network-perimeter deployments. If patching cannot be completed immediately, restrict network access to the UniFi Connect Application management interface using firewall rules or network segmentation, limiting exposure to trusted administrative hosts only. Monitor host-level logs on UniFi Connect Application servers for anomalous process spawning, unexpected outbound connections, or shell execution events that may indicate exploitation attempts. Check Ubiquiti's official security advisories and the UniFi release notes for the specific patched version and apply it without delay given the maximum CVSS score assigned to this vulnerability.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →