A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 26 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection Enabling Privilege Escalation in UniFi Talk Application

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection Enabling Privilege Escalation in UniFi Talk Application

Tue, 21 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title SQL Injection Vulnerability Allowing Privilege Escalation in Ubiquiti UniFi Talk Application

Wed, 15 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title SQL Injection Vulnerability Allowing Privilege Escalation in Ubiquiti UniFi Talk Application

Tue, 14 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection in UniFi Talk Enabling Privilege Escalation

Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection in UniFi Talk Enabling Privilege Escalation

Mon, 13 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection Enables Privilege Escalation in UniFi Talk Application

Sat, 11 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection Enables Privilege Escalation in UniFi Talk Application

Fri, 10 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection Enables Privilege Escalation in UniFi Talk

Thu, 09 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection Enables Privilege Escalation in UniFi Talk

Wed, 08 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Elevated Privileges via Authenticated SQL Injection in UniFi Talk Application

Tue, 07 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Elevated Privileges via Authenticated SQL Injection in UniFi Talk Application

Mon, 06 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection Enables Privilege Escalation in UniFi Talk

Mon, 06 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection Enables Privilege Escalation in UniFi Talk

Sun, 05 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection in UniFi Talk Allows Privilege Escalation

Sun, 05 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection in UniFi Talk Allows Privilege Escalation

Sun, 05 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Authenticated SQL Injection in UniFi Talk Application

Sat, 04 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Authenticated SQL Injection in UniFi Talk Application

Sat, 04 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Authenticated SQL Injection in UniFi Talk Application

Sat, 04 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Authenticated SQL Injection in UniFi Talk Application

Fri, 03 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Multiple Authenticated SQL Injection Vulnerabilities in UniFi Talk Enabling Privilege Escalation

Fri, 03 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Multiple Authenticated SQL Injection Vulnerabilities in UniFi Talk Enabling Privilege Escalation

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-02T15:52:10.116Z

Reserved: 2026-06-06T15:00:09.780Z

Link: CVE-2026-50747

cve-icon Vulnrichment

Updated: 2026-07-02T15:41:34.962Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T23:30:04Z

Weaknesses