Critical Command‑Injection & Privilege‑Escalation Flaws in Ubiquiti UniFi OS (CVE‑2026‑50746 et al.)
What It Is – Ubiquiti disclosed seven critical vulnerabilities in its UniFi OS suite. The highest‑severity issue, CVE‑2026‑50746 (CVSS 10.0), permits unauthenticated command injection in the UniFi Connect application. Other flaws (CVE‑2026‑50747 – CVE‑2026‑55116) enable SQL injection, SSRF, CORS misuse and improper access‑control, all leading to privilege escalation on managed devices such as smart‑lighting controllers and EV‑charger gateways.
Exploitability – All flaws are exploitable by a low‑privileged attacker with network access; no public exploits or confirmed wild‑use have been reported yet, but the CVSS scores (9.0‑10.0) indicate a very high likelihood of successful exploitation once a proof‑of‑concept is released.
Affected Products – UniFi Connect (v 3.4.16‑ and earlier), UniFi Talk, UniFi Access, UniFi Protect and other UniFi OS‑based appliances that manage building‑automation and IoT workloads.
Why It Matters for Compliance & Audit Readiness
- Control Mapping – The flaws expose gaps in Access Control (CC6.1) and Change Management (CC7.2) that must be mapped to SOC 2 criteria and continuously monitored.
- Evidence of Due Diligence – Demonstrating timely patching and verification provides audit‑ready evidence that the organization maintains a robust vulnerability‑management process (CC4.1).
- Defensible Audit Trail – Continuous collection of patch‑status data (e.g., via Verisq’s Control Mapping) helps prove to auditors that remediation actions were taken within the required timeframes.
Recommended Actions
- Immediately apply the UniFi OS security bulletin 066 patches to all affected devices.
- Update your asset inventory and map each patched component to the relevant SOC 2 controls (Access Control, Change Management, System Operations).
- Capture patch‑deployment logs as immutable evidence for audit readiness.
- Review network segmentation to limit lateral movement from compromised IoT devices.
Source: Security Affairs – Ubiquiti Patches Critical UniFi OS Flaws