Catchify Blog
Expert insights on cybersecurity, penetration testing, and protecting your digital assets

Pre-Auth RCE in UniFi OS - CVE-2026-34909: One Request to Root Behind Seven Products ($42,751)
Four chained vulnerabilities: SQL injection in UniFi Talk, OS command injection with root escalation in UniFi Access, a path-traversal authorization bypass (CVSS 10.0), and an unauthenticated token-minting pre-auth RCE, awarded $42,751 across four CVEs.

Leaking 2M+ Records and Documents Without Attacking Core Application
How misconfigured Salesforce Aura endpoints and Zendesk integrations led to mass PII disclosure of 2M+ records and full takeover of WhatsApp, email, X DMs, and chatbot support channels.

CVE-2025-52665 - RCE in Unifi Access ($25,000)
During a security assessment, we identified a critical unauthenticated Remote Code Execution vulnerability in UniFi OS that was rewarded $25,000. This write-up details the discovery process, exploitation, and remediation of this critical security flaw.