VULNERABILITY OVERVIEW
An improper access control (CWE-284) flaw in UniFi Connect Application allows any network-adjacent attacker to perform OS-level command injection on the host device without authentication. The flaw is part of Ubiquiti Security Advisory Bulletin 066, which disclosed 25 vulnerabilities across UniFi Connect, Talk, Access, Protect, and OS; Censys estimates ~100,000 UniFi OS endpoints are internet-accessible. No confirmed in-the-wild exploitation at time of writing, but a structurally identical prior CVE chain (CVE-2026-34908/09/10) was added to CISA KEV in June after real-world attacks. Patch to UniFi Connect Application 3.4.20 or later.
CVSS BREAKDOWN
↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
NONE
⊕
Scope / Impact
CHANGED
C:H · I:H · A:H
AFFECTED VERSIONS
UniFi Connect Application versions 3.4.16 and earlierCITATIONS
- → https://thehackernews.com/2026/07/ubiquiti-patches-critical-unifi-flaws.html
- → https://fieldeffect.com/blog/ubiquiti-patches-multiple-critical-vulnerabilities-in-unifi-products/
- → https://www.techtimes.com/articles/319919/20260708/unifi-cvss-100-flaw-exposes-100000-endpoints-unauthenticated-takeover.htm
- → https://cybersecuritynews.com/ubiquiti-disclosed-25-flaws/