Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-50748: UniFi Access Application: Malicious code execution via network access
CVE-2026-50748
CVE-2026-50748
Summary
A vulnerability in UniFi Access Application allows an attacker with low-level access to the network to potentially execute malicious code on the device. This could lead to unauthorized access or disruption of the network. It is recommended to update the UniFi Access Application to the latest version to mitigate this risk.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ubiquiti inc | unifi access application | < 4.2.29 |
| ui | unifi_access_application |
< 4.2.29 cpe:2.3:a:ui:unifi_access_application:*:*:*:*:*:*:*:* |
Original title
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host...
Original description
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.
nvd CVSS3.1
9.9
Vulnerability type
CWE-20
Improper Input Validation
Published: 2 Jul 2026 · Updated: 23 Jul 2026 · First seen: 2 Jul 2026